Back

CVE-2005-3952

SQL injection vulnerability in PHP Labs Top Auction allows remote attackers to execute arbitrary SQL commands via the (1) category and (2) type parameters to viewcat.php, or (3) certain search parameters. NOTE: later a disclosure reported the affected version as 1.0.

Published: Dec 1, 2005 Modified: Jun 16, 2026
CWE-89

CVSS Metrics

Affected Products (1)

Vendor Product Version
php_labs top_auction 1.0

GitHub Security Advisory GHSA-xrfv-jpgw-xhww

SQL injection vulnerability in PHP Labs Top Auction allows remote attackers to execute arbitrary...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 2.52%

Top 16% most likely to be exploited

Threat Score 30.8 / 100

Data Sources

NVD EPSS GitHub