CVE-2005-3838 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 1.5% (pctl 73)
Patch early
A public exploit exists.
Description
Multiple SQL injection vulnerabilities in search.php in IsolSoft Support Center 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) lorder, (2) Priority, (3) Status, (4) Category, (5) searchvalue, and (6) field parameter.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 1.46% — more likely to be exploited than 73% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2005-11-26 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| isolsoft | support center |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | IsolSoft Support Center 2.2 - Multiple SQL Injections | 2005-11-25 |
References
- http://pridels0.blogspot.com/2005/11/isolsoft-support-center-sql-inj.html
- http://secunia.com/advisories/17728
- http://securitytracker.com/id?1015270
- http://www.osvdb.org/21102
- http://www.securityfocus.com/bid/15570
- http://www.vupen.com/english/advisories/2005/2592
- http://pridels0.blogspot.com/2005/11/isolsoft-support-center-sql-inj.html
- http://secunia.com/advisories/17728
- http://securitytracker.com/id?1015270
- http://www.osvdb.org/21102
- http://www.securityfocus.com/bid/15570
- http://www.vupen.com/english/advisories/2005/2592
→ the Explorer · watch your stack · NVD