peter bassill · operator
$ cve CVE-2004-1402 JSON

CVE-2004-1402 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 3.3% (pctl 88)

Patch early

A public exploit exists.

Description

SQL injection vulnerability in iWebNegar allows remote attackers to execute arbitrary SQL commands via (1) the string parameter for index.php, (2) comments.php, or (3) the administrator login page.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS3.29% — more likely to be exploited than 88% of all CVEs
On CISA KEVno
Public exploityes
Published2004-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
iwebnegariwebnegar

Public exploits

SourceTitleDate
exploit-dbIWebNegar - Multiple SQL Injections2004-12-15

References

→ the Explorer  ·  watch your stack  ·  NVD