CVE-2005-4606
Web Wiz Database Login <1.71, Journal <1.0, Site News <3.06, Weekly Poll <3.06 - SQL Injection
Title source: llmDescription
SQL injection vulnerability in check_user.asp in multiple Web Wiz products including (1) Site News 3.06 and earlier, (2) Journal 1.0 and earlier, (3) Polls 3.06 and earlier, and (4) and Database Login 1.71 and earlier allows remote attackers to execute arbitrary SQL commands via the txtUserName parameter.
References (6)
Core 6
Core References
Third Party Advisory third-party-advisory
x_refsource_sreason
http://securityreason.com/securityalert/305
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2006/0007
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/22148
Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/18263
Exploit vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/16085
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/420551/100/0/threaded
Scores
EPSS
0.0148
EPSS Percentile
71.4%
Details
CWE
CWE-89
Status
published
Products (5)
webwiz/database_login
< 1.71
webwiz/journal
< 1.0
webwiz/site_news
2.00
webwiz/site_news
< 3.06
webwiz/weekly_poll
< 3.06
Published
Dec 31, 2005
Tracked Since
Feb 18, 2026