Back

CVE-2005-3844

SQL injection vulnerability in phpWordPress PHP News and Article Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the (1) poll and (2) category parameters to index.php, and (3) the ctg parameter in an archive action.

Published: Nov 26, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
phpwordpress php_news_and_article_manager 3.0

GitHub Security Advisory GHSA-f7vw-x862-7chj

SQL injection vulnerability in phpWordPress PHP News and Article Manager 3.0 allows remote...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.23%

Top 33% most likely to be exploited

Threat Score 30.4 / 100

Data Sources

NVD EPSS GitHub