CVE Vulnerabilities

CVE-2005-4140

Published: Dec 09, 2005 | Modified: Oct 19, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

SQL injection vulnerability in admin/login/index.php in Website Baker 2.6.0 allows remote attackers to execute arbitrary SQL commands via the username parameter, as used by the user field.

Affected Software

Name Vendor Start Version End Version
Website_baker Website_baker 2.5.2 (including) 2.5.2 (including)
Website_baker Website_baker 2.6 (including) 2.6 (including)

References