Back

CVE-2006-0135

SQL injection vulnerability in login.php in TheWebForum (twf) 1.2.1 allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the username parameter (aka the u variable).

Published: Jan 9, 2006 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
thewebforum thewebforum *

GitHub Security Advisory GHSA-456x-j3xw-5vwm

SQL injection vulnerability in login.php in TheWebForum (twf) 1.2.1 allows remote attackers to...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 2.32%

Top 18% most likely to be exploited

Threat Score 30.7 / 100

Data Sources

NVD EPSS GitHub