VYPR
Unrated severityNVD Advisory· Published Nov 17, 2005· Updated Jun 16, 2026

CVE-2005-3646

CVE-2005-3646

Description

Multiple SQL injection vulnerabilities in lib-sessions.inc.php in phpAdsNew and phpPgAds 2.0.6 and possibly earlier versions allow remote attackers to execute arbitrary SQL commands via the sessionID parameter in (1) logout.php and (2) index.php.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

11
  • cpe:2.3:a:phpadsnew:phpadsnew:2.0.4_pr1:*:*:*:*:*:*:*+ 8 more
    • cpe:2.3:a:phpadsnew:phpadsnew:2.0.4_pr1:*:*:*:*:*:*:*
    • cpe:2.3:a:phpadsnew:phpadsnew:2.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:phpadsnew:phpadsnew:2.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:phpadsnew:phpadsnew:2.0.7_rc1:*:*:*:*:*:*:*
    • cpe:2.3:a:phpadsnew:phpadsnew:2.0_beta5:*:*:*:*:*:*:*
    • cpe:2.3:a:phpadsnew:phpadsnew:2.0_beta6:*:*:*:*:*:*:*
    • cpe:2.3:a:phpadsnew:phpadsnew:2_dev_2001-09-30:*:*:*:*:*:*:*
    • cpe:2.3:a:phpadsnew:phpadsnew:2_dev_2001-10-09:*:*:*:*:*:*:*
    • (no CPE)range: <=2.0.6
  • Phppgads/Phppgads2 versions
    cpe:2.3:a:phppgads:phppgads:2.0.6:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:phppgads:phppgads:2.0.6:*:*:*:*:*:*:*
    • (no CPE)range: <=2.0.6

Patches

Vulnerability mechanics

References

15

News mentions

0

No linked articles in our index yet.