Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2005-4159

EPSS 1.11% · P78
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2005-4159

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
NOTE: this issue has been disputed by the vendor and third parties. SQL injection vulnerability in Memberlist.php in Simple Machines Forum (SMF) 1.1 rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter. NOTE: the vendor says that since only one character can be modified, there is no SQL injection. Thus this might be an "invalid SQL syntax error." Multiple followups support the vendor
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Simple Machines Forum (SMF) Memberlist.php SQL注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
** 争议 ** Simple Machines Forum (SMF) 1.1 rc1 以及更早版本中的Memberlist.php中的SQL注入漏洞,远程攻击者可以通过start参数执行任意SQL命令。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2005-4159

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2005-4159

登录查看更多情报信息。

Same Patch Batch · n/a · 2005-12-11 · 27 CVEs total

CVE-2005-4161MilliScripts Register.PHP 跨站脚本漏洞
CVE-2005-3532Courier Mail Server未授权访问漏洞
CVE-2005-4158Sudo Perl环境变量处理安全性绕过漏洞
CVE-2005-4157Kerio WinRoute Firewall未明漏洞
CVE-2005-4156Mambo未明漏洞
CVE-2005-4155ATutor Registration.PHP SQL注入漏洞
CVE-2005-4154PEAR installer 未明漏洞
CVE-2005-4153GNU Mailman大型日期数据拒绝服务漏洞
CVE-2005-4152Soti Pocket Controller-Professional远程命令执行漏洞
CVE-2005-3533Mike Neuman OSH命令行参数缓冲区溢出漏洞
CVE-2005-4164PHP-地址簿 view.php SQL注入漏洞
CVE-2005-4163Captcha PHP captcha.php 目录遍历漏洞
CVE-2005-4162ACME Perl-Cal Cal_make.PL 跨站脚本漏洞
CVE-2005-4165ASP-DEV XM Forum Forum.ASP 多个跨站脚本漏洞
CVE-2005-4160Torrential Getdox.PHP 目录遍历漏洞
CVE-2005-4176多个提供商 BIOS 键盘缓冲密码持久性漏洞
CVE-2005-4175多个提供商 BIOS 键盘缓冲密码持久性漏洞
CVE-2005-4174eFiction多个远程输入验证漏洞
CVE-2005-4173eFiction多个远程输入验证漏洞
CVE-2005-4172eFiction多个远程输入验证漏洞

Showing top 20 of 27 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2005-4159

No comments yet


Leave a comment