Back

CVE-2005-2896

SQL injection vulnerability in WEB//NEWS 1.4 allows remote attackers to execute arbitrary SQL commands via the (1) wn_userpw parameter to startup.php, (2) cat, (3) id, or (4) stof parameter to news.php, or (5) id parameter to print.php.

Published: Sep 14, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
stylemotion web_news 1.4

GitHub Security Advisory GHSA-xm2g-rgpw-75v4

SQL injection vulnerability in WEB//NEWS 1.4 allows remote attackers to execute arbitrary SQL...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.17%

Top 35% most likely to be exploited

Threat Score 30.4 / 100

Data Sources

NVD EPSS GitHub