peter bassill · operator
$ cve CVE-2005-0413 JSON

CVE-2005-0413 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.1% (pctl 81)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in MyPHP Forum 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the fid in forum.php, (2) the member parameter in member.php, (3) the email parameter in forgot.php, or (4) the nbuser or nbpass parameters in include.php. NOTE: it was later reported that vector 2 exists in 3.0 and earlier.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.09% — more likely to be exploited than 81% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2005-04-27
Last modified2026-06-16

Affected (1)

VendorProduct
myphp forummyphp forum

Public exploits

SourceTitleDate
exploit-dbMyPHP Forum 1.0 - SQL Injection2005-02-10

References

→ the Explorer  ·  watch your stack  ·  NVD