CVE-2005-4001
phpYellowTM Pro and Lite Edition 5.33 - SQL Injection via Haystack or Ckey Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2005-4001. PoCs published by r0t3d3Vil.
AI-analyzed exploit summary The provided text describes SQL injection vulnerabilities in phpYellowTM due to improper input sanitization. It includes a sample URL demonstrating the vulnerability but lacks executable exploit code.
Description
Multiple SQL injection vulnerabilities in phpYellowTM Pro Edition and Lite Edition 5.33 allow remote attackers to execute arbitrary SQL commands via the (1) haystack parameter to search_result.php or (2) ckey parameter to print_me.php.
Exploits (2)
The provided text describes SQL injection vulnerabilities in phpYellowTM due to improper input sanitization. It includes a sample URL demonstrating the vulnerability but lacks executable exploit code.
The provided text describes a SQL injection vulnerability in phpYellowTM, where the 'ckey' parameter in 'print_me.php' is not properly sanitized. It references a SecurityFocus BID but does not include actual exploit code.