CVE-2005-4226

phpwebthings < 1.4 - SQL Injection via Multiple Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2005-4226. PoCs published by rgod.

AI-analyzed exploit summary This PHP script exploits SQL injection vulnerabilities in PHPWebThings 1.4 via the 'msg' and 'forum' parameters, allowing administrative credential disclosure and remote command execution. It includes functionality to bypass magic_quotes_gpc and supports proxy usage.

Description

Multiple "potential" SQL injection vulnerabilities in phpWebThings 1.4 Patched might allow remote attackers to execute arbitrary SQL commands via (1) the ref parameter in download.php, (2) the direction, msg, sforum, reason, subname, and toform parameters in forum.php, (3) the msg and forum parameters in forum_edit.php, (4) the msg and forum parameters in forum_write.php, (5) the tekst parameter in guestbook.php, (6) the menuoption parameter in index.php, and the (7) sel_avatar parameter in myaccount.php. NOTE: the forum.php/forum vector is already identified by CVE-2005-3585.

Exploits (2)

exploitdb WORKING POC VERIFIED
by rgod · phpwebappsphp
https://www.exploit-db.com/exploits/1324

This PHP script exploits SQL injection vulnerabilities in PHPWebThings 1.4 via the 'msg' and 'forum' parameters, allowing administrative credential disclosure and remote command execution. It includes functionality to bypass magic_quotes_gpc and supports proxy usage.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: PHPWebThings 1.4
No auth needed
Prerequisites: Target running PHPWebThings 1.4 · Network access to the target
devstral-2 · analyzed Feb 18, 2026 Full analysis →
exploitdb WORKING POC
perlwebappsphp
https://www.exploit-db.com/exploits/1325

This Perl script exploits a SQL injection vulnerability in phpwebthing v1.4.4 by injecting a UNION-based query to retrieve the MD5 hash of a user's password from the database. It uses LWP::Simple to send the crafted request and extracts the hash from the response.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: phpwebthing v1.4.4
No auth needed
Prerequisites: Target URL · User ID
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (13)

Core 13
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/21653
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/21650
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/18011/
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/21654
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/23565
Various Sources x_refsource_misc
http://glide.stanford.edu/yichen/research/sec.pdf
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/21651
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/21656
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/419280/100/0/threaded
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2005/2860
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/419487/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/21655
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/21652

Scores

EPSS 0.0228
EPSS Percentile 85.1%

Details

Status published
Products (1)
phpwebthings/phpwebthings < 1.4
Published Dec 14, 2005
Tracked Since Feb 18, 2026