Back

CVE-2005-4619

SQL injection vulnerability in index.php in phpoutsourcing Zorum Forum 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the rollid parameter in the showhtmllist method.

Published: Dec 31, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (6)

Vendor Product Version
phpoutsourcing zorum 3.0
phpoutsourcing zorum 3.1
phpoutsourcing zorum 3.2
phpoutsourcing zorum 3.3
phpoutsourcing zorum 3.4
phpoutsourcing zorum 3.5

GitHub Security Advisory GHSA-wrx8-cxgj-cgpv

SQL injection vulnerability in index.php in phpoutsourcing Zorum Forum 3.5 and earlier allows...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.15%

Top 36% most likely to be exploited

Threat Score 30.3 / 100

Data Sources

NVD EPSS GitHub