Back

CVE-2004-2322

SQL injection vulnerability in the (1) announce and (2) notes modules of phpWebSite before 0.9.3-2 allows remote attackers to execute arbitrary SQL queries, as demonstrated using the ANN_id parameter to the announce module.

Published: Dec 31, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (6)

Vendor Product Version
phpwebsite phpwebsite 0.9.0
phpwebsite phpwebsite 0.9.1
phpwebsite phpwebsite 0.9.2
phpwebsite phpwebsite 0.9.2.1
phpwebsite phpwebsite 0.9.3
phpwebsite phpwebsite 0.9.3.1

GitHub Security Advisory GHSA-hv4w-w4qm-8h45

SQL injection vulnerability in the (1) announce and (2) notes modules of phpWebSite before 0.9.3...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.51%

Top 28% most likely to be exploited

Threat Score 30.5 / 100

Data Sources

NVD EPSS GitHub