CVE-2005-4071
Last modified
CVE-2005-4071 is a vulnerability of currently unknown severity. Multiple SQL injection vulnerabilities in CFMagic Magic Forum Personal 2.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ForumID parameter in view_forum.cfm, and (2) ForumID, (3) Thread, and (4) ThreadID parameters in view_thread.cfm.. EPSS estimates a 1.26% chance of exploitation in the next 30 days.
Description
Multiple SQL injection vulnerabilities in CFMagic Magic Forum Personal 2.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ForumID parameter in view_forum.cfm, and (2) ForumID, (3) Thread, and (4) ThreadID parameters in view_thread.cfm.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cfmagic | Magic Forum Personal | <= 2.5 |
References
- http://secunia.com/advisories/17935Vendor Advisory
- http://www.vupen.com/english/advisories/2005/2794Vendor Advisory
- http://secunia.com/advisories/17935Vendor Advisory
- http://www.vupen.com/english/advisories/2005/2794Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-4071?
How severe is CVE-2005-4071?
How do I fix CVE-2005-4071?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-4065SQL injection vulnerability in the search module in Edgewall…
- CVE-2005-4066Total Commander 6.53 uses weak encryption to store FTP usern…
- CVE-2005-4067Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2005-4068Unspecified "absolute path vulnerability" in umountall in IB…
- CVE-2005-4069SunnComm MediaMax DRM 5.0.21.0, as used by Sony BMG, assigns…
- CVE-2005-4070Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2005-4072Cross-site scripting (XSS) vulnerability in CFMagic Magic Fo…
- CVE-2005-4073SQL injection vulnerability in view_archive.cfm in CFMagic M…
- CVE-2005-4074Directory traversal vulnerability in index.cfm in CF_Nuke 4.…
- CVE-2005-4075Multiple cross-site scripting (XSS) vulnerabilities in index…
- CVE-2005-4076Buffer overflow in Appfluent Technology Database IDS 2.0 all…
- CVE-2005-4077Multiple off-by-one errors in the cURL library (libcurl) 7.1…
Are you affected by CVE-2005-4071?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
