{
    "id": "CVE-2005-3838",
    "published": "2005-11-26 22:03:00",
    "last_modified": "2026-06-16 22:17:43",
    "cvss_score": "7.5",
    "cvss_severity": "HIGH",
    "cvss_version": "2.0",
    "cvss_vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
    "cwe": null,
    "description": "Multiple SQL injection vulnerabilities in search.php in IsolSoft Support Center 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) lorder, (2) Priority, (3) Status, (4) Category, (5) searchvalue, and (6) field parameter.",
    "epss_score": "0.01459",
    "epss_percentile": "0.72819",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-10-11 18:17:04",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "isolsoft",
            "product": "support_center"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "26595",
            "title": "IsolSoft Support Center 2.2 - Multiple SQL Injections",
            "date": "2005-11-25",
            "url": "https://www.exploit-db.com/exploits/26595"
        }
    ],
    "refs_list": [
        "http://pridels0.blogspot.com/2005/11/isolsoft-support-center-sql-inj.html",
        "http://secunia.com/advisories/17728",
        "http://securitytracker.com/id?1015270",
        "http://www.osvdb.org/21102",
        "http://www.securityfocus.com/bid/15570",
        "http://www.vupen.com/english/advisories/2005/2592",
        "http://pridels0.blogspot.com/2005/11/isolsoft-support-center-sql-inj.html",
        "http://secunia.com/advisories/17728",
        "http://securitytracker.com/id?1015270",
        "http://www.osvdb.org/21102",
        "http://www.securityfocus.com/bid/15570",
        "http://www.vupen.com/english/advisories/2005/2592"
    ]
}