CVE-2005-3938 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 3.8% (pctl 90)
Patch early
A public exploit exists.
Description
SQL injection vulnerability in Softbiz FAQ Script 1.1 and earler allows remote attackers to execute arbitrary SQL commands via the id parameter in (1) index.php, (2) faq_qanda.php, (3) refer_friend.php, (4) print_article.php, or (5) add_comment.php.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 3.82% — more likely to be exploited than 90% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2005-12-01 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| softbizscripts | faq script |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | SoftBiz FAQ 1.1 - 'index.php?cid' SQL Injection | 2005-11-30 |
| exploit-db | SoftBiz FAQ 1.1 - 'faq_qanda.php?id' SQL Injection | 2005-11-30 |
| exploit-db | SoftBiz FAQ 1.1 - 'refer_friend.php?id' SQL Injection | 2005-11-30 |
| exploit-db | SoftBiz FAQ 1.1 - 'print_article.php?id' SQL Injection | 2005-11-30 |
| exploit-db | SoftBiz FAQ 1.1 - 'add_comment.php?id' SQL Injection | 2005-11-30 |
References
- http://pridels0.blogspot.com/2005/11/softbiz-faq-script-multiple-sql-vuln.html
- http://secunia.com/advisories/17809
- http://www.osvdb.org/21257
- http://www.osvdb.org/21258
- http://www.osvdb.org/21259
- http://www.osvdb.org/21260
- http://www.osvdb.org/21261
- http://www.securityfocus.com/bid/15653
- http://pridels0.blogspot.com/2005/11/softbiz-faq-script-multiple-sql-vuln.html
- http://secunia.com/advisories/17809
- http://www.osvdb.org/21257
- http://www.osvdb.org/21258
- http://www.osvdb.org/21259
- http://www.osvdb.org/21260
- http://www.osvdb.org/21261
- http://www.securityfocus.com/bid/15653
→ the Explorer · watch your stack · NVD