Back

CVE-2005-0725

SQL injection vulnerability in the getAllbyArticle function in wfsfiles.php for WF-Sections (wfsections) 1.07 allows remote attackers to execute arbitrary SQL commands via the articleid parameter to article.php.

Published: Mar 8, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
wf-sections wf-sections 1.07

GitHub Security Advisory GHSA-w26q-jp2w-2hvw

SQL injection vulnerability in the getAllbyArticle function in wfsfiles.php for WF-Sections ...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.04%

Top 39% most likely to be exploited

Threat Score 30.3 / 100

Data Sources

NVD EPSS GitHub