CVE Vulnerabilities

CVE-2005-4286

Published: Dec 16, 2005 | Modified: Mar 08, 2011
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Unspecified vulnerability in PhpLogCon before 1.2.2 allows remote attackers to use arbitrary profiles via unknown vectors involving smart values for userid and password, probably involving an SQL injection vulnerability in the (1) pass and (2) usr parameters in submit.php.

Affected Software

Name Vendor Start Version End Version
Phplogcon Phplogcon 1.2.1 1.2.1
Phplogcon Phplogcon 1.1.0 1.1.0
Phplogcon Phplogcon 1.2.0 1.2.0

References