CVE-2005-0669
Multiple SQL injection vulnerabilities in mod.php for phpCOIN 1.2.0 through 1.2.1b allow remote attackers to execute arbitrary SQL commands via the (1) the faq_id in the faq mod, (2) the id parameter in the pages mod, (3) the id parameter in the…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.57%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple SQL injection vulnerabilities in mod.php for phpCOIN 1.2.0 through 1.2.1b allow remote attackers to execute arbitrary SQL commands via the (1) the faq_id in the faq mod, (2) the id parameter in the pages mod, (3) the id parameter in the siteinfo module, (4) the topic_id parameter in the articles module, (5) the ord_id in the orders module, (6) the dom_id parameter in the domains module, or (7) the invd_id parameter in the invoices module.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.57% probability · 74th percentile
- CISA KEV
- Not listed
- Affected
- coinsoft technologies/phpcoin
- Source
- cve@mitre.org
References
- http://forums.phpcoin.com/index.php?showtopic=4101
- http://forums.phpcoin.com/index.php?showtopic=4116Patch
- http://forums.phpcoin.com/index.php?showtopic=4118
- http://lostmon.blogspot.com/2005/03/phpcoin-posible-sql-injection-comands.htmlExploit
- http://secunia.com/advisories/14439Exploit, Patch
- http://securitytracker.com/id?1013329Exploit
- http://www.securityfocus.com/bid/12686Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19571
- http://forums.phpcoin.com/index.php?showtopic=4101
- http://forums.phpcoin.com/index.php?showtopic=4116Patch
- http://forums.phpcoin.com/index.php?showtopic=4118
- http://lostmon.blogspot.com/2005/03/phpcoin-posible-sql-injection-comands.htmlExploit
- http://secunia.com/advisories/14439Exploit, Patch
- http://securitytracker.com/id?1013329Exploit
- http://www.securityfocus.com/bid/12686Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19571
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.