{"api_version":"1","generated_at":"2026-07-23T11:29:41+00:00","cve":"CVE-2004-2067","urls":{"html":"https://cve.report/CVE-2004-2067","api":"https://cve.report/api/cve/CVE-2004-2067.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-2067","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-2067"},"summary":{"title":"CVE-2004-2067","description":"SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attackers to execute arbitrary SQL and bypass authentication via the (1) user, (2) password, or (3) crypted_password parameters.","state":"PUBLISHED","assigner":"mitre","published_at":"2004-07-29 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.jaws.com.mx/index.php?gadget=blog&action=single_view&id=10","name":"http://www.jaws.com.mx/index.php?gadget=blog&action=single_view&id=10","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Planet Jaws","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/10826","name":"http://www.securityfocus.com/bid/10826","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"JAWS ControlPanel.PHP SQL Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.osvdb.org/8320","name":"http://www.osvdb.org/8320","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://marc.info/?l=bugtraq&m=109116345930380&w=2","name":"http://marc.info/?l=bugtraq&m=109116345930380&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/16847","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/16847","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1010815","name":"http://securitytracker.com/id?1010815","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Jaws 'controlpanel.php' Input Validation Error Lets Remote Users Inject SQL Commands to Gain Administrative Access - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-2067","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-2067","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"2067","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"jaws","cpe5":"jaws","cpe6":"0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"2067","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"jaws","cpe5":"jaws","cpe6":"0.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"2067","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"jaws","cpe5":"jaws","cpe6":"0.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T01:15:01.357Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"10826","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/10826"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.jaws.com.mx/index.php?gadget=blog&action=single_view&id=10"},{"name":"20040729 Jaws 0.4: authentication bypass","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=109116345930380&w=2"},{"name":"8320","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/8320"},{"name":"1010815","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1010815"},{"name":"jaws-controlpanel-sql-injection(16847)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/16847"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-07-29T00:00:00.000Z","descriptions":[{"lang":"en","value":"SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attackers to execute arbitrary SQL and bypass authentication via the (1) user, (2) password, or (3) crypted_password parameters."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"10826","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/10826"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.jaws.com.mx/index.php?gadget=blog&action=single_view&id=10"},{"name":"20040729 Jaws 0.4: authentication bypass","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=109116345930380&w=2"},{"name":"8320","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/8320"},{"name":"1010815","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1010815"},{"name":"jaws-controlpanel-sql-injection(16847)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/16847"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-2067","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attackers to execute arbitrary SQL and bypass authentication via the (1) user, (2) password, or (3) crypted_password parameters."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"10826","refsource":"BID","url":"http://www.securityfocus.com/bid/10826"},{"name":"http://www.jaws.com.mx/index.php?gadget=blog&action=single_view&id=10","refsource":"CONFIRM","url":"http://www.jaws.com.mx/index.php?gadget=blog&action=single_view&id=10"},{"name":"20040729 Jaws 0.4: authentication bypass","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=109116345930380&w=2"},{"name":"8320","refsource":"OSVDB","url":"http://www.osvdb.org/8320"},{"name":"1010815","refsource":"SECTRACK","url":"http://securitytracker.com/id?1010815"},{"name":"jaws-controlpanel-sql-injection(16847)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/16847"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-2067","datePublished":"2005-05-10T04:00:00.000Z","dateReserved":"2005-05-04T00:00:00.000Z","dateUpdated":"2024-08-08T01:15:01.357Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-07-29 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:jaws:jaws:0.2:*:*:*:*:*:*:*","matchCriteriaId":"CA6406F9-BE2A-4127-B5CC-D2BFE56212B2"},{"vulnerable":true,"criteria":"cpe:2.3:a:jaws:jaws:0.3:*:*:*:*:*:*:*","matchCriteriaId":"15BFB2A5-78DF-40AE-B0DD-C79D5052C642"},{"vulnerable":true,"criteria":"cpe:2.3:a:jaws:jaws:0.4:*:*:*:*:*:*:*","matchCriteriaId":"3C529BB5-608A-4AEB-A6D2-E40F2C3C0CA3"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"2067","Ordinal":"1","Title":"CVE-2004-2067","CVE":"CVE-2004-2067","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"2067","Ordinal":"1","NoteData":"SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attackers to execute arbitrary SQL and bypass authentication via the (1) user, (2) password, or (3) crypted_password parameters.","Type":"Description","Title":"CVE-2004-2067"},{"CveYear":"2004","CveId":"2067","Ordinal":"2","NoteData":"2005-05-10","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"2067","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}