Unrated severityNVD Advisory· Published Jan 17, 2005· Updated Apr 16, 2026
CVE-2005-0292
CVE-2005-0292
Description
Multiple SQL injection vulnerabilities in index.php in PHP Gift Registry (phpGiftReg) 1.4.0, and possibly other versions before 1.5.0b1, allow remote attackers to execute arbitrary SQL commands via the (1) messageid, (2) shopper, (3) shopfor, or (4) itemid parameters.
Affected products
1- cpe:2.3:a:php_gift_registry:phpgiftreg:1.4:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- www.securityfocus.com/archive/1/392485nvdPatchVendor Advisory
- www.securityfocus.com/bid/12289nvdPatchVendor Advisory
- lists.grok.org.uk/pipermail/full-disclosure/2005-January/030965.htmlnvdExploitVendor Advisory
- secunia.com/advisories/13873nvdVendor Advisory
- marc.infonvd
- securitytracker.com/idnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/18925nvd
News mentions
0No linked articles in our index yet.