PT-2005-1742 · Phpmyfaq · Phpmyfaq

Published

2005-03-07

·

Updated

2008-09-05

·

CVE-2005-0702

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions phpMyFAQ versions 1.4 through 1.5
Description The issue allows remote attackers to add FAQ records to the database via the username field in forum messages, potentially leading to unauthorized data modification.
Recommendations For phpMyFAQ versions 1.4 through 1.5, update to a version that includes a fix for this issue to prevent SQL injection attacks.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0702

Affected Products

Phpmyfaq