Back

CVE-2004-2067

SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attackers to execute arbitrary SQL and bypass authentication via the (1) user, (2) password, or (3) crypted_password parameters.

Published: Jul 29, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (3)

Vendor Product Version
jaws jaws 0.2
jaws jaws 0.3
jaws jaws 0.4

GitHub Security Advisory GHSA-qc4q-f89m-cc5m

SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 2.80%

Top 15% most likely to be exploited

Threat Score 30.8 / 100

Data Sources

NVD EPSS GitHub