Back
CVE-2005-4606
SQL injection vulnerability in check_user.asp in multiple Web Wiz products including (1) Site News 3.06 and earlier, (2) Journal 1.0 and earlier, (3) Polls 3.06 and earlier, and (4) and Database Login 1.71 and earlier allows remote attackers to execute arbitrary SQL commands via the txtUserName parameter.
Published: Dec 31, 2005
Modified: Jun 16, 2026
CWE-89
CVSS Metrics
Affected Products (5)
| Vendor | Product | Version |
|---|---|---|
| webwiz | database_login | * |
| webwiz | journal | * |
| webwiz | site_news | * |
| webwiz | site_news | 2.00 |
| webwiz | weekly_poll | * |
GitHub Security Advisory GHSA-439v-qhv3-9f5x
SQL injection vulnerability in check_user.asp in multiple Web Wiz products including (1) Site...
References (12)
- http://secunia.com/advisories/18263 Patch, Vendor Advisory
- http://securityreason.com/securityalert/305
- http://www.osvdb.org/22148
- http://www.securityfocus.com/archive/1/420551/100/0/threaded
- http://www.securityfocus.com/bid/16085 Exploit
- http://www.vupen.com/english/advisories/2006/0007
- http://secunia.com/advisories/18263 Patch, Vendor Advisory
- http://securityreason.com/securityalert/305
- http://www.osvdb.org/22148
- http://www.securityfocus.com/archive/1/420551/100/0/threaded
- http://www.securityfocus.com/bid/16085 Exploit
- http://www.vupen.com/english/advisories/2006/0007
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
1.48%
Top 28% most likely to be exploited
Threat Score
30.4 / 100
Data Sources
NVD
EPSS
GitHub