CVE-2005-4001

Phpyellowtm Lite - SQL Injection

Title source: rule

Description

Multiple SQL injection vulnerabilities in phpYellowTM Pro Edition and Lite Edition 5.33 allow remote attackers to execute arbitrary SQL commands via the (1) haystack parameter to search_result.php or (2) ckey parameter to print_me.php.

Exploits (2)

exploitdb WRITEUP VERIFIED
by r0t3d3Vil · textwebappsphp
https://www.exploit-db.com/exploits/26713
exploitdb WRITEUP VERIFIED
by r0t3d3Vil · textwebappsphp
https://www.exploit-db.com/exploits/26714

Scores

EPSS 0.0058
EPSS Percentile 68.6%

Classification

Status draft

Affected Products (2)

phpyellow/phpyellowtm_lite
phpyellow/phpyellowtm_pro

Timeline

Published Dec 05, 2005
Tracked Since Feb 18, 2026