CVE-2005-0368 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.3% (pctl 83)
Patch early
A public exploit exists.
Description
Multiple SQL injection vulnerabilities in CMScore allow remote attackers to execute arbitrary SQL commands via the (1) EntryID or (2) searchterm parameter to index.php, or (3) username parameter to authenticate.php.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.33% — more likely to be exploited than 83% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2005-05-02 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| chipmunk scripts | cmscore |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | CMScore - SQL Injection | 2005-02-10 |
References
- http://marc.info/?l=bugtraq&m=110803385223054&w=2
- http://secunia.com/advisories/14142/
- http://www.securityfocus.com/bid/12457
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19235
- http://marc.info/?l=bugtraq&m=110803385223054&w=2
- http://secunia.com/advisories/14142/
- http://www.securityfocus.com/bid/12457
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19235
→ the Explorer · watch your stack · NVD