VulnerabilityModified
CVE-2005-4743
Multiple SQL injection vulnerabilities in index.php in NeLogic Nephp Publisher 4.5.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) nnet_catid parameters.
MEDIUM 5.0EPSS 1.14%
Does this matter?
Lower severity and a low EPSS score (1.14%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple SQL injection vulnerabilities in index.php in NeLogic Nephp Publisher 4.5.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) nnet_catid parameters.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 1.14% probability · 65th percentile
- CISA KEV
- Not listed
- Affected
- nelogic technologies/nephp publisher
- Source
- cve@mitre.org
References
- http://pridels0.blogspot.com/2005/11/nephp-publisher-v45x-sql-inj-vuln.html
- http://secunia.com/advisories/17772Vendor Advisory
- http://www.osvdb.org/21196
- http://pridels0.blogspot.com/2005/11/nephp-publisher-v45x-sql-inj-vuln.html
- http://secunia.com/advisories/17772Vendor Advisory
- http://www.osvdb.org/21196
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.