Files
CVEs-PoC/2005/CVE-2005-3682.md
T
2024-06-18 02:51:15 +02:00

18 lines
711 B
Markdown

### [CVE-2005-3682](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3682)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
Multiple SQL injection vulnerabilities in Wizz Forum 1.20 allow remote attackers to execute arbitrary SQL commands via (1) the AuthID parameter in ForumAuthDetails.php, and the TopicID parameter in (2) ForumTopicDetails.php and (3) ForumReply.php.
### POC
#### Reference
- http://securityreason.com/securityalert/181
#### Github
No PoCs found on GitHub currently.