CVE-2005-0475
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 1.0%
from disclosure to weapon0 days
Published on NVDFeb 19
1st PoCFeb 17
exploitation probability
1.0%top 39% of all CVEs
observed exploitation
nono source reports it
4 public exploit(s)
SQL injection vulnerability in paFAQ Beta4, and possibly other versions, allows remote attackers to execute arbitrary SQL code via the (1) offset, (2) limit, (3) order, or (4) orderby parameter to question.php, (5) offset parameter to answer.php, (6) search_item parameter to search.php, (7) cat_id, (8) cid, or (9) id parameter to comment.php.
Affected products
n/a · n/apublic PoCs found — 4✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/25115exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/25116exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/25117exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/25114⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.