CVE-2005-4606
Last modified
CVE-2005-4606 is a vulnerability of currently unknown severity. SQL injection vulnerability in check_user.asp in multiple Web Wiz products including (1) Site News 3.06 and earlier, (2) Journal 1.0 and earlier, (3) Polls 3.06 and earlier, and (4) and Database Login 1.71 and earlier allows remote attackers to execute arbitrary SQL commands via the txtUserName parameter.. EPSS estimates a 1.48% chance of exploitation in the next 30 days.
Description
SQL injection vulnerability in check_user.asp in multiple Web Wiz products including (1) Site News 3.06 and earlier, (2) Journal 1.0 and earlier, (3) Polls 3.06 and earlier, and (4) and Database Login 1.71 and earlier allows remote attackers to execute arbitrary SQL commands via the txtUserName parameter.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Webwiz | Database Login | <= 1.71 |
| Webwiz | Journal | <= 1.0 |
| Webwiz | Site News | <= 3.06 |
| Webwiz | Site News | 2.00 |
| Webwiz | Weekly Poll | <= 3.06 |
References
- http://secunia.com/advisories/18263Patch, Vendor Advisory
- http://secunia.com/advisories/18263Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-4606?
How severe is CVE-2005-4606?
How do I fix CVE-2005-4606?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-4600Directory traversal vulnerability in tiny_mce_gzip.php in Ti…
- CVE-2005-4601The delegate code in ImageMagick 6.2.4.5-0.3 allows remote a…
- CVE-2005-4602SQL injection vulnerability in inc/function_upload.php in My…
- CVE-2005-4603Cross-site scripting (XSS) vulnerability in printthread.php …
- CVE-2005-4604Buffer overflow in MTink in the printer-filters-utils packag…
- CVE-2005-4605The procfs code (proc_misc.c) in Linux 2.6.14.3 and other ve…
- CVE-2005-4607Cross-site scripting (XSS) vulnerability in index.php in Bug…
- CVE-2005-4608SQL injection vulnerability in index.php in BugPort 1.147 al…
- CVE-2005-4609index.php in BugPort 1.147 and earlier allows remote attacke…
- CVE-2005-4610Format string vulnerability in the server for Dopewars befor…
- CVE-2005-4611SQL injection vulnerability in search.php in Free ClickBank …
- CVE-2005-4612Multiple SQL injection vulnerabilities in VUBB alpha rc1 all…
Are you affected by CVE-2005-4606?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
