peter bassill · operator
$ cve CVE-2005-4195 JSON

CVE-2005-4195 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 5.5% (pctl 93)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in Scout Portal Toolkit (SPT) 1.3.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the ParentId parameter in SPT--BrowseResources.php, (2) ResourceId parameter in SPT--FullRecord.php, (3) ResourceOffset parameter in SPT--Home.php, and (4) F_UserName and (5) F_Password in SPT--UserLogin.php. NOTE: it was later reported that vector 1 is also present in 1.4.0.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS5.5% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2005-12-13
Last modified2026-06-16

Affected (2)

VendorProduct
internet scoutscout portal toolkit
internet scout projectscout portal toolkit

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD