CVE-2005-3920

Babe Logger 2 - SQL Injection via gal or id Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2005-3920. PoCs published by r0t.

AI-analyzed exploit summary The provided text describes a SQL injection vulnerability in Babe Logger, where the 'gal' parameter in index.php is not properly sanitized. It references a security advisory but does not include functional exploit code.

Description

SQL injection vulnerability in Babe Logger 2 allows remote attackers to execute arbitrary SQL commands via the (1) gal parameter to index.php or (2) id parameter to comments.php.

Exploits (2)

exploitdb WRITEUP VERIFIED
by r0t · textwebappsphp
https://www.exploit-db.com/exploits/26605

The provided text describes a SQL injection vulnerability in Babe Logger, where the 'gal' parameter in index.php is not properly sanitized. It references a security advisory but does not include functional exploit code.

Classification
Writeup 80%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: Babe Logger (version not specified)
No auth needed
Prerequisites: Access to the vulnerable application
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by r0t · textwebappsphp
https://www.exploit-db.com/exploits/26606

The provided text describes a SQL injection vulnerability in Babe Logger, where the 'id' parameter in comments.php is not properly sanitized. It references a SecurityFocus advisory but lacks actual exploit code or a proof-of-concept.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: Babe Logger (version unspecified)
No auth needed
Prerequisites: Access to the vulnerable comments.php endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/21206
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/21205
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17767
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/15580

Scores

EPSS 0.0117
EPSS Percentile 63.4%

Details

Status published
Products (1)
babe_logger/babe_logger 2
Published Nov 30, 2005
Tracked Since Feb 18, 2026