VYPR
Unrated severityNVD Advisory· Published Nov 16, 2005· Updated Apr 16, 2026

CVE-2005-3553

CVE-2005-3553

Description

Multiple SQL injection vulnerabilities in include.php in PHPKIT 1.6.1 R2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in conjunction with the login/userinfo.php path and (2) the session parameter (aka the PHPKITSID variable).

Affected products

1
  • cpe:2.3:a:phpkit:phpkit:*:rc2:*:*:*:*:*:*
    Range: <=1.6.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

10

News mentions

0

No linked articles in our index yet.