CVE-2005-4001

phpYellowTM Pro and Lite Edition 5.33 - SQL Injection via Haystack or Ckey Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2005-4001. PoCs published by r0t3d3Vil.

AI-analyzed exploit summary The provided text describes SQL injection vulnerabilities in phpYellowTM due to improper input sanitization. It includes a sample URL demonstrating the vulnerability but lacks executable exploit code.

Description

Multiple SQL injection vulnerabilities in phpYellowTM Pro Edition and Lite Edition 5.33 allow remote attackers to execute arbitrary SQL commands via the (1) haystack parameter to search_result.php or (2) ckey parameter to print_me.php.

Exploits (2)

exploitdb WRITEUP VERIFIED
by r0t3d3Vil · textwebappsphp
https://www.exploit-db.com/exploits/26713

The provided text describes SQL injection vulnerabilities in phpYellowTM due to improper input sanitization. It includes a sample URL demonstrating the vulnerability but lacks executable exploit code.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: phpYellowTM (version not specified)
No auth needed
Prerequisites: Access to the vulnerable application
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by r0t3d3Vil · textwebappsphp
https://www.exploit-db.com/exploits/26714

The provided text describes a SQL injection vulnerability in phpYellowTM, where the 'ckey' parameter in 'print_me.php' is not properly sanitized. It references a SecurityFocus BID but does not include actual exploit code.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: phpYellowTM (version not specified)
No auth needed
Prerequisites: Access to the vulnerable endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2005/2722
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17849
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/21428
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/21429
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/15700

Scores

EPSS 0.0129
EPSS Percentile 66.4%

Details

Status published
Products (2)
phpyellow/phpyellowtm_lite 5.33
phpyellow/phpyellowtm_pro 5.33
Published Dec 05, 2005
Tracked Since Feb 18, 2026