CVE-2005-1384
Multiple SQL injection vulnerabilities in phpCoin 1.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to index.php, (2) phpcoinsessid parameter to login.php, (3) id, (4) dtopic_id, or (5) dcat_id to mod.php.
- Affected products
- Phpcoin
- Coinsoft Technologies Phpcoin
- = 1.2, 1.2.1, 1.2.1b
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 2.7% (85th percentile)
- NVD status
- Modified
- Published
- 2005-05-02
CVE-2005-1384 at NVD
2 known exploits for CVE-2005-1384
Proof-of-concept code and exploit modules indexed by Sploitus