CVE-2005-3937
Summary
| CVE | CVE-2005-3937 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-12-01 06:03:00 UTC |
| Updated | 2026-04-06 14:41:30 UTC |
| Description | SQL injection vulnerability in Softbiz B2B Trading Marketplace Script 1.1 and earler allows remote attackers to execute arbitrary SQL commands via the cid parameter in (1) selloffers.php, (2) buyoffers.php, (3) products.php, or (4) profiles.php. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS: 0.008210000 probability, percentile 0.743650000 (date 2026-04-07)
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Softbizscripts | B2b Trading Marketplace Script | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.osvdb.org/21252 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | Broken Link |
| Softbiz B2B Trading Marketplace Multiple SQL Injection Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Broken Link |
| www.osvdb.org/21254 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | Broken Link |
| - UNSECURED SYSTEMS -: Softbiz B2B trading Marketplace Script SQL inj. | af854a3a-2127-422b-91ae-364da2661108 | pridels0.blogspot.com | Broken Link |
| www.osvdb.org/21255 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | Broken Link |
| Secunia - Advisories - Softbiz B2B Trading Marketplace Script "cid" SQL Injection | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| www.osvdb.org/21253 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | Broken Link |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.