Back

CVE-2005-0946

SQL injection vulnerability in phpCoin 1.2.1b and earlier allows remote attackers to execute arbitrary SQL commands via the (1) term/keywords field on the search page, (2) username or (3) e-mail field on the forgot password page, or (4) domain name on the ordering new package page.

Published: Mar 29, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (3)

Vendor Product Version
coinsoft_technologies phpcoin 1.2
coinsoft_technologies phpcoin 1.2.1
coinsoft_technologies phpcoin 1.2.1b

GitHub Security Advisory GHSA-2wjr-3qh4-v657

SQL injection vulnerability in phpCoin 1.2.1b and earlier allows remote attackers to execute...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.20%

Top 35% most likely to be exploited

Threat Score 30.4 / 100

Data Sources

NVD EPSS GitHub