CVE-2005-0858

CoolForum < 0.8 - SQL Injection via Pseudo or Login Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2005-0858. PoCs published by Romano.

AI-analyzed exploit summary The provided text describes SQL injection and XSS vulnerabilities in CoolForum, with an example SQL injection payload. However, it lacks executable exploit code, making it a vulnerability writeup rather than a functional PoC.

Description

Multiple SQL injection vulnerabilities in CoolForum 0.8 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the pseudo parameter to entete.php or (2) the login parameter to register.php.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Romano · textwebappsphp
https://www.exploit-db.com/exploits/25240

The provided text describes SQL injection and XSS vulnerabilities in CoolForum, with an example SQL injection payload. However, it lacks executable exploit code, making it a vulnerability writeup rather than a functional PoC.

Classification
Writeup 90%
Attack Type
Sqli | Xss
Complexity
Trivial
Reliability
Theoretical
Target: CoolForum (version unspecified)
No auth needed
Prerequisites: Access to the target application's registration endpoint
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/19761
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/19759
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/12852
Exploit, Patch vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1013474

Scores

EPSS 0.0123
EPSS Percentile 65.9%

Details

Status published
Products (1)
coolforum/coolforum < 0.8
Published May 02, 2005
Tracked Since Feb 18, 2026