CVE-2005-0475

paFAQ Beta4 - SQL Injection via Multiple Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 4 public exploits for CVE-2005-0475. PoCs published by pi3ch.

AI-analyzed exploit summary The provided text describes an SQL injection vulnerability in paFaq beta4, where the 'search_item' parameter in the URL is not properly sanitized. The example URL demonstrates a basic SQLi attempt using a single quote, but no actual exploit code is included.

Description

SQL injection vulnerability in paFAQ Beta4, and possibly other versions, allows remote attackers to execute arbitrary SQL code via the (1) offset, (2) limit, (3) order, or (4) orderby parameter to question.php, (5) offset parameter to answer.php, (6) search_item parameter to search.php, (7) cat_id, (8) cid, or (9) id parameter to comment.php.

Exploits (4)

exploitdb WRITEUP VERIFIED
by pi3ch · textwebappsphp
https://www.exploit-db.com/exploits/25116

The provided text describes an SQL injection vulnerability in paFaq beta4, where the 'search_item' parameter in the URL is not properly sanitized. The example URL demonstrates a basic SQLi attempt using a single quote, but no actual exploit code is included.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: paFaq beta4
No auth needed
Prerequisites: Access to the vulnerable paFaq application
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by pi3ch · textwebappsphp
https://www.exploit-db.com/exploits/25114

The provided text describes an SQL injection vulnerability in paFaq beta4, detailing multiple attack vectors via unsanitized input in the 'orderby', 'order', and 'limit' parameters. No actual exploit code is present, only example URLs demonstrating the vulnerability.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: paFaq beta4
No auth needed
Prerequisites: Access to the vulnerable web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by pi3ch · textwebappsphp
https://www.exploit-db.com/exploits/25117

The provided text describes an SQL injection vulnerability in paFaq beta4, with example URLs demonstrating how unsanitized input in the 'cat_id', 'cid', and 'id' parameters can be exploited. No actual exploit code is present.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: paFaq beta4
No auth needed
Prerequisites: Access to the vulnerable paFaq application
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by pi3ch · textwebappsphp
https://www.exploit-db.com/exploits/25115

The provided text describes an SQL injection vulnerability in paFaq beta4, where the 'offset' parameter in the URL is not properly sanitized. The example URL demonstrates a basic SQLi attempt but lacks executable exploit code.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: paFaq beta4
No auth needed
Prerequisites: Access to the vulnerable application URL
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=110868808723487&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/19371

Scores

EPSS 0.0101
EPSS Percentile 58.8%

Details

Status published
Products (1)
php_arena/pafaq beta4
Published Mar 30, 2005
Tracked Since Feb 18, 2026