CVE-2004-1962

Protector System 1.15b1 - SQL Injection via Comment Sequence Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2004-1962. PoCs published by waraxe.

AI-analyzed exploit summary The provided text describes SQL injection and XSS vulnerabilities in Protector System 1.15b1 for PHP-Nuke, including example exploit URLs. No actual exploit code is present, only descriptions and proof-of-concept URLs.

Description

SQL injection vulnerability in index.php in Protector System 1.15b1 allows remote attackers to bypass SQL injection filters by using "/**/" sequences in the targeted fields.

Exploits (1)

exploitdb WRITEUP VERIFIED
by waraxe · textwebappsphp
https://www.exploit-db.com/exploits/24047

The provided text describes SQL injection and XSS vulnerabilities in Protector System 1.15b1 for PHP-Nuke, including example exploit URLs. No actual exploit code is present, only descriptions and proof-of-concept URLs.

Classification
Writeup 90%
Attack Type
Sqli | Xss
Complexity
Trivial
Reliability
Theoretical
Target: Protector System 1.15b1 for PHP-Nuke
No auth needed
Prerequisites: Access to the target web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/361300/2004-04-21/2004-04-27/0
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/10206
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/15969
Various Sources x_refsource_confirm
http://protector.warcenter.se/article-53--0-0.html

Scores

EPSS 0.0120
EPSS Percentile 64.1%

Details

Status published
Products (1)
protector_system/protector_system 1.15b1
Published Dec 31, 2004
Tracked Since Feb 18, 2026