{"api_version":"1","generated_at":"2026-07-23T08:09:05+00:00","cve":"CVE-2005-0271","urls":{"html":"https://cve.report/CVE-2005-0271","api":"https://cve.report/api/cve/CVE-2005-0271.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-0271","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-0271"},"summary":{"title":"CVE-2005-0271","description":"Multiple SQL injection vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to showcat.php or (2) product parameter to addfav.php.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-01-03 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18732","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18732","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=110485682424110&w=2","name":"http://marc.info/?l=bugtraq&m=110485682424110&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'Serious Vulnerabilities In PhotoPost ReviewPost' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.gulftech.org/?node=research&article_id=00062-01022005","name":"http://www.gulftech.org/?node=research&article_id=00062-01022005","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch","Vendor Advisory"],"title":"Contact Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/13697/","name":"http://secunia.com/advisories/13697/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch","Vendor Advisory"],"title":"Secunia - Advisories - ReviewPost PHP Pro Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-0271","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-0271","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"271","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"photopost","cpe5":"reviewpost_php_pro","cpe6":"1.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"271","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"photopost","cpe5":"reviewpost_php_pro","cpe6":"2.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"271","vulnerable":"1","versionEndIncluding":"2.5.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"photopost","cpe5":"reviewpost_php_pro","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T21:05:25.416Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.gulftech.org/?node=research&article_id=00062-01022005"},{"name":"reviewpost-php-sql-injection(18732)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18732"},{"name":"13697","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/13697/"},{"name":"20050103 Serious Vulnerabilities In PhotoPost ReviewPost","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=110485682424110&w=2"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-01-03T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple SQL injection vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to showcat.php or (2) product parameter to addfav.php."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://www.gulftech.org/?node=research&article_id=00062-01022005"},{"name":"reviewpost-php-sql-injection(18732)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18732"},{"name":"13697","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/13697/"},{"name":"20050103 Serious Vulnerabilities In PhotoPost ReviewPost","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=110485682424110&w=2"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-0271","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple SQL injection vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to showcat.php or (2) product parameter to addfav.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.gulftech.org/?node=research&article_id=00062-01022005","refsource":"MISC","url":"http://www.gulftech.org/?node=research&article_id=00062-01022005"},{"name":"reviewpost-php-sql-injection(18732)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18732"},{"name":"13697","refsource":"SECUNIA","url":"http://secunia.com/advisories/13697/"},{"name":"20050103 Serious Vulnerabilities In PhotoPost ReviewPost","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=110485682424110&w=2"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-0271","datePublished":"2005-02-10T05:00:00.000Z","dateReserved":"2005-02-10T00:00:00.000Z","dateUpdated":"2024-08-07T21:05:25.416Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-01-03 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:photopost:reviewpost_php_pro:*:*:*:*:*:*:*:*","versionEndIncluding":"2.5.1","matchCriteriaId":"BC8DE8E6-00CB-46CC-9C9A-537AEDF74A91"},{"vulnerable":true,"criteria":"cpe:2.3:a:photopost:reviewpost_php_pro:1.0.2:*:*:*:*:*:*:*","matchCriteriaId":"A201E3C2-98CE-493C-AD53-B33088954268"},{"vulnerable":true,"criteria":"cpe:2.3:a:photopost:reviewpost_php_pro:2.5:*:*:*:*:*:*:*","matchCriteriaId":"790D2CB2-EF2B-43C6-AE21-ECC5BA6C73C5"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"271","Ordinal":"1","Title":"CVE-2005-0271","CVE":"CVE-2005-0271","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"271","Ordinal":"1","NoteData":"Multiple SQL injection vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to showcat.php or (2) product parameter to addfav.php.","Type":"Description","Title":"CVE-2005-0271"},{"CveYear":"2005","CveId":"271","Ordinal":"2","NoteData":"2005-02-10","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"271","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}