peter bassill · operator
$ cve CVE-2005-2468 JSON

CVE-2005-2468 EXPLOIT

6.4
MEDIUM · CVSS 2.0 · EPSS 2% (pctl 81)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) isCorrectPassword or (2) userExist function in class.auth.php, getCustomFieldReport function in (4) custom_fields.php, (5) custom_fields_graph.php, or (6) class.report.php, or the insert function in (7) releases.php or (8) class.release.php.

Scoring

CVSS6.4 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
EPSS2.04% — more likely to be exploited than 81% of all CVEs
On CISA KEVno
Public exploityes
Published2005-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
mysqleventum

Public exploits

SourceTitleDate
exploit-dbMySQL Eventum 1.5.5 - 'login.php' SQL Injection2005-08-05

References

→ the Explorer  ·  watch your stack  ·  NVD