CVE-2005-3236
Last modified
CVE-2005-3236 is a vulnerability of currently unknown severity. Multiple SQL injection vulnerabilities in Cyphor 0.19 allow remote attackers to execute arbitrary SQL and obtain administrative access via (1) the fid parameter of newmsg.php, which can enable XSS attacks when the SQL syntax is invalid or (2) the nick parameter of lostpwd.php.. EPSS estimates a 3.69% chance of exploitation in the next 30 days.
Description
Multiple SQL injection vulnerabilities in Cyphor 0.19 allow remote attackers to execute arbitrary SQL and obtain administrative access via (1) the fid parameter of newmsg.php, which can enable XSS attacks when the SQL syntax is invalid or (2) the nick parameter of lostpwd.php.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cynox | Cyphor | 0.19 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-3236?
How severe is CVE-2005-3236?
How do I fix CVE-2005-3236?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-3230Multiple interpretation error in unspecified versions of Pan…
- CVE-2005-3231Multiple interpretation error in unspecified versions of CAT…
- CVE-2005-3232Multiple interpretation error in unspecified versions of The…
- CVE-2005-3233Multiple interpretation error in unspecified versions of Tru…
- CVE-2005-3234Multiple interpretation error in unspecified versions of Gri…
- CVE-2005-3235Multiple interpretation error in unspecified versions of Pro…
- CVE-2005-3237Cross-site scripting (XSS) vulnerability in Cyphor 0.19 allo…
- CVE-2005-3238Multiple unspecified vulnerabilities in Solaris 10 SCTP Sock…
- CVE-2005-3239The OLE2 unpacker in clamd in Clam AntiVirus (ClamAV) 0.87-1…
- CVE-2005-3240Race condition in Microsoft Internet Explorer allows user-as…
- CVE-2005-3241Multiple vulnerabilities in Ethereal 0.10.12 and earlier all…
- CVE-2005-3242Ethereal 0.10.12 and earlier allows remote attackers to caus…
Are you affected by CVE-2005-3236?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
