SQL Injection Vulnerability in PHPX 3.5.9 and Earlier: Bypass Authentication and Arbitrary Code Execution

SQL Injection Vulnerability in PHPX 3.5.9 and Earlier: Bypass Authentication and Arbitrary Code Execution

CVE-2005-3968 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

SQL injection vulnerability in auth.inc.php in PHPX 3.5.9 and earlier allows remote attackers to execute arbitrary SQL commands, bypass authentication, and upload arbitrary PHP code via the username parameter.

Learn more about our User Device Pen Test.