Back

CVE-2005-4606

SQL injection vulnerability in check_user.asp in multiple Web Wiz products including (1) Site News 3.06 and earlier, (2) Journal 1.0 and earlier, (3) Polls 3.06 and earlier, and (4) and Database Login 1.71 and earlier allows remote attackers to execute arbitrary SQL commands via the txtUserName parameter.

Published: Dec 31, 2005 Modified: Jun 16, 2026
CWE-89

CVSS Metrics

Affected Products (5)

Vendor Product Version
webwiz database_login *
webwiz journal *
webwiz site_news *
webwiz site_news 2.00
webwiz weekly_poll *

GitHub Security Advisory GHSA-439v-qhv3-9f5x

SQL injection vulnerability in check_user.asp in multiple Web Wiz products including (1) Site...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.48%

Top 28% most likely to be exploited

Threat Score 30.4 / 100

Data Sources

NVD EPSS GitHub