Back

CVE-2005-2486

SQL injection vulnerability in mod_forum/read_message.php in PortailPHP allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php with the affiche parameter set to "Forum-read_mess", a different vulnerability than CVE-2005-1701.

Published: Aug 7, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
portailphp portailphp 2.4

GitHub Security Advisory GHSA-xcx5-f4xc-rcg7

SQL injection vulnerability in mod_forum/read_message.php in PortailPHP allows remote attackers...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.15%

Top 36% most likely to be exploited

Threat Score 30.3 / 100

Data Sources

NVD EPSS GitHub