Back

CVE-2005-3363

SQL injection vulnerability in Saphp Lesson, possibly saphp Lesson1.1 and saphpLesson2.0, allows remote attackers to execute arbitrary SQL commands via the forumid parameter in (1) showcat.php and (2) add.php.

Published: Oct 30, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
saphp saphplesson 1.1
saphp saphplesson 2.0

GitHub Security Advisory GHSA-8hjw-x28q-9fwc

SQL injection vulnerability in Saphp Lesson, possibly saphp Lesson1.1 and saphpLesson2.0, allows...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 3.48%

Top 12% most likely to be exploited

Threat Score 31 / 100

Data Sources

NVD EPSS GitHub