Back
CVE-2005-4286
Unspecified vulnerability in PhpLogCon before 1.2.2 allows remote attackers to use arbitrary profiles via unknown vectors involving "'smart' values for userid and password," probably involving an SQL injection vulnerability in the (1) pass and (2) usr parameters in submit.php.
Published: Dec 16, 2005
Modified: Jun 16, 2026
CVSS Metrics
GitHub Security Advisory GHSA-wmr5-5jr5-6x3m
Unspecified vulnerability in PhpLogCon before 1.2.2 allows remote attackers to use arbitrary...
References (8)
- http://cvs.sourceforge.net/viewcvs.py/phplogcon/phplogcon/submit.php?r1=1.4&r2=1.5
- http://secunia.com/advisories/18053 Patch, Vendor Advisory
- http://www.phplogcon.com/Article9.phtml
- http://www.vupen.com/english/advisories/2005/2930
- http://cvs.sourceforge.net/viewcvs.py/phplogcon/phplogcon/submit.php?r1=1.4&r2=1.5
- http://secunia.com/advisories/18053 Patch, Vendor Advisory
- http://www.phplogcon.com/Article9.phtml
- http://www.vupen.com/english/advisories/2005/2930
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
1.21%
Top 34% most likely to be exploited
Threat Score
30.4 / 100
Data Sources
NVD
EPSS
GitHub