CVE-2005-3555
phplist < 2.10.1 - Authenticated SQL Injection via id Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2005-3555. PoCs published by Tobias Klein.
AI-analyzed exploit summary The provided text describes multiple input validation vulnerabilities in PHPList, including SQL injection via the 'id' parameter in the 'editattributes' page. It lacks executable exploit code but outlines attack vectors.
Description
Multiple SQL injection vulnerabilities in PHPlist 2.10.1 and earlier allow authenticated remote attackers with administrator privileges to execute arbitrary SQL commands via the id parameter in the (1) editattributes or (2) admin page.
Exploits (2)
The provided text describes multiple input validation vulnerabilities in PHPList, including SQL injection via the 'id' parameter in the 'editattributes' page. It lacks executable exploit code but outlines attack vectors.
The provided text describes multiple input validation vulnerabilities in PHPList, including SQL injection, XSS, HTTP injection, and directory traversal. It includes a basic example URL demonstrating a potential SQL injection vector.