PT-2005-1742 · Phpmyfaq · Phpmyfaq
Published
2005-03-07
·
Updated
2008-09-05
·
CVE-2005-0702
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
phpMyFAQ versions 1.4 through 1.5
Description
The issue allows remote attackers to add FAQ records to the database via the
username field in forum messages, potentially leading to unauthorized data modification.Recommendations
For phpMyFAQ versions 1.4 through 1.5, update to a version that includes a fix for this issue to prevent SQL injection attacks.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phpmyfaq