CVE Vulnerabilities

CVE-2005-4001

Published: Dec 05, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Multiple SQL injection vulnerabilities in phpYellowTM Pro Edition and Lite Edition 5.33 allow remote attackers to execute arbitrary SQL commands via the (1) haystack parameter to search_result.php or (2) ckey parameter to print_me.php.

Affected Software

NameVendorStart VersionEnd Version
Phpyellowtm_litePhpyellow5.33 (including)5.33 (including)
Phpyellowtm_proPhpyellow5.33 (including)5.33 (including)

References