High severity7.3NVD Advisory· Published Jul 13, 2022· Updated Jun 17, 2026
CVE-2017-20128
CVE-2017-20128
Description
A vulnerability has been found in KB Messages PHP Script 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument username/password with the input 'or''=' leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- cpe:2.3:a:kb_messages_php_script_project:kb_messages_php_script:1.0:*:*:*:*:*:*:*
- unspecified/KB Messages PHP Scriptv5Range: 1.0
Patches
Vulnerability mechanics
References
2- www.exploit-db.com/exploits/41168/nvdExploitThird Party AdvisoryVDB Entry
- vuldb.comnvdPermissions RequiredThird Party Advisory
News mentions
0No linked articles in our index yet.