CVE-2005-3938 describes a critical SQL injection vulnerability affecting Softbiz FAQ Script versions 1.1 and earlier. This flaw allows unauthenticated remote attackers to execute arbitrary SQL commands by manipulating the 'id' parameter across multiple PHP scripts within the application. With a CVSS v2 score of 7.5 (High), it presents a significant risk, potentially leading to full compromise of data confidentiality, integrity, and availability with low attack complexity. Although not observed in active exploitation or listed on the CISA KEV catalog, multiple public exploit proofs-of-concept are readily available on ExploitDB. Community discussion and media coverage surrounding this vulnerability remain minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.1CPE matchmatch criteria | cpe:2.3:a:softbizscripts:faq_script:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.