CVE-2004-1402 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 3.3% (pctl 88)
Patch early
A public exploit exists.
Description
SQL injection vulnerability in iWebNegar allows remote attackers to execute arbitrary SQL commands via (1) the string parameter for index.php, (2) comments.php, or (3) the administrator login page.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 3.29% — more likely to be exploited than 88% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2004-12-31 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| iwebnegar | iwebnegar |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | IWebNegar - Multiple SQL Injections | 2004-12-15 |
References
→ the Explorer · watch your stack · NVD