CVE-2005-4218

Phpwebthings - SQL Injection

Title source: rule

Description

SQL injection vulnerability in forum.php in PHPWebThings 1.4 allows remote attackers to execute arbitrary SQL commands via the msg parameter, a different vulnerability than CVE-2005-3585.

Exploits (2)

exploitdb WORKING POC VERIFIED
by rgod · phpwebappsphp
https://www.exploit-db.com/exploits/1324
exploitdb WORKING POC VERIFIED
by AhLam · perlwebappsphp
https://www.exploit-db.com/exploits/1325

Scores

EPSS 0.0059
EPSS Percentile 69.2%

Details

Status published
Products (1)
phpwebthings/phpwebthings 1.4
Published Dec 14, 2005
Tracked Since Feb 18, 2026