Unrated severityNVD Advisory· Published Sep 14, 2005· Updated Apr 16, 2026
CVE-2005-2896
CVE-2005-2896
Description
SQL injection vulnerability in WEB//NEWS 1.4 allows remote attackers to execute arbitrary SQL commands via the (1) wn_userpw parameter to startup.php, (2) cat, (3) id, or (4) stof parameter to news.php, or (5) id parameter to print.php.
Affected products
1- cpe:2.3:a:stylemotion:web_news:1.4:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.securityfocus.com/bid/14776nvdExploit
- secunia.com/advisories/16727/nvdVendor Advisory
- marc.infonvd
- exchange.xforce.ibmcloud.com/vulnerabilities/22179nvd
News mentions
0No linked articles in our index yet.