← Back

CVE-2005-0475

nvd nist
Published: Mar 30, 2005Modified: Apr 16, 2026

JSON object

Loading...
6.4
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:N
Exploitability: 10.0 / Impact: 4.9
Source: NVD

Description

SQL injection vulnerability in paFAQ Beta4, and possibly other versions, allows remote attackers to execute arbitrary SQL code via the (1) offset, (2) limit, (3) order, or (4) orderby parameter to question.php, (5) offset parameter to answer.php, (6) search_item parameter to search.php, (7) cat_id, (8) cid, or (9) id parameter to comment.php.

Affected (1)

Products: Php Arena: Pafaq
1 product
Pafaq
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version beta4

References (4)

Timeline

No history available yet.