Back

CVE-2005-4140

SQL injection vulnerability in admin/login/index.php in Website Baker 2.6.0 allows remote attackers to execute arbitrary SQL commands via the username parameter, as used by the user field.

Published: Dec 9, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
website_baker website_baker 2.5.2
website_baker website_baker 2.6

GitHub Security Advisory GHSA-q5fc-7mw8-7mpw

SQL injection vulnerability in admin/login/index.php in Website Baker 2.6.0 allows remote...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 2.16%

Top 19% most likely to be exploited

Threat Score 30.6 / 100

Data Sources

NVD EPSS GitHub