Back
CVE-2005-4546
search.php in eggblog 2.0 allows remote attackers to obtain the full path via an invalid q parameter, as used by the Keyword and Search fields, possibly due to an SQL injection vulnerability.
Published: Dec 28, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| epic_designs | eggblog | * |
GitHub Security Advisory GHSA-cfq8-fj46-w8p7
search.php in eggblog 2.0 allows remote attackers to obtain the full path via an invalid q...
References (12)
- http://pridels0.blogspot.com/2005/12/eggblog-vuln.html
- http://secunia.com/advisories/18212 Vendor Advisory
- http://www.osvdb.org/21908
- http://www.securityfocus.com/bid/16056
- http://www.vupen.com/english/advisories/2005/3072
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23857
- http://pridels0.blogspot.com/2005/12/eggblog-vuln.html
- http://secunia.com/advisories/18212 Vendor Advisory
- http://www.osvdb.org/21908
- http://www.securityfocus.com/bid/16056
- http://www.vupen.com/english/advisories/2005/3072
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23857
Risk Scores
CVSS Score
7.8 / 10
EPSS Score
1.59%
Top 26% most likely to be exploited
Threat Score
31.7 / 100
Data Sources
NVD
EPSS
GitHub