Back
CVE-2004-2067
SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attackers to execute arbitrary SQL and bypass authentication via the (1) user, (2) password, or (3) crypted_password parameters.
Published: Jul 29, 2004
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (3)
| Vendor | Product | Version |
|---|---|---|
| jaws | jaws | 0.2 |
| jaws | jaws | 0.3 |
| jaws | jaws | 0.4 |
GitHub Security Advisory GHSA-qc4q-f89m-cc5m
SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0...
References (12)
- http://marc.info/?l=bugtraq&m=109116345930380&w=2
- http://securitytracker.com/id?1010815
- http://www.jaws.com.mx/index.php?gadget=blog&action=single_view&id=10
- http://www.osvdb.org/8320
- http://www.securityfocus.com/bid/10826 Exploit, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16847
- http://marc.info/?l=bugtraq&m=109116345930380&w=2
- http://securitytracker.com/id?1010815
- http://www.jaws.com.mx/index.php?gadget=blog&action=single_view&id=10
- http://www.osvdb.org/8320
- http://www.securityfocus.com/bid/10826 Exploit, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16847
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
2.80%
Top 15% most likely to be exploited
Threat Score
30.8 / 100
Data Sources
NVD
EPSS
GitHub