{"api_version":"1","generated_at":"2026-07-24T21:43:05+00:00","cve":"CVE-2005-0292","urls":{"html":"https://cve.report/CVE-2005-0292","api":"https://cve.report/api/cve/CVE-2005-0292.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-0292","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-0292"},"summary":{"title":"CVE-2005-0292","description":"Multiple SQL injection vulnerabilities in index.php in PHP Gift Registry (phpGiftReg) 1.4.0, and possibly other versions before 1.5.0b1, allow remote attackers to execute arbitrary SQL commands via the (1) messageid, (2) shopper, (3) shopfor, or (4) itemid parameters.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-01-17 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://secunia.com/advisories/13873","name":"http://secunia.com/advisories/13873","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - PHP Gift Registry SQL Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/12289","name":"http://www.securityfocus.com/bid/12289","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"PHP Gift Registry Multiple SQL Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030965.html","name":"http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030965.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"[Full-Disclosure] phpGiftReq SQL Injection","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18925","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18925","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/392485","name":"http://www.securityfocus.com/archive/1/392485","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=110599710017066&w=2","name":"http://marc.info/?l=bugtraq&m=110599710017066&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'phpGiftReq SQL Injection' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1012910","name":"http://securitytracker.com/id?1012910","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - PHP Gift Registry Parameter Input Validation Hole Lets Remote Users Inject SQL Commands","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-0292","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-0292","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"292","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"php_gift_registry","cpe5":"phpgiftreg","cpe6":"1.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T21:05:25.474Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"12289","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/12289"},{"name":"1012910","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1012910"},{"name":"phpgiftregistry-sql-injection(18925)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18925"},{"name":"20050307 Re: phpGiftReq SQL Injection","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/392485"},{"name":"13873","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/13873"},{"name":"20050116 phpGiftReq SQL Injection","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=110599710017066&w=2"},{"name":"20050116 phpGiftReq SQL Injection","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030965.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-01-16T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple SQL injection vulnerabilities in index.php in PHP Gift Registry (phpGiftReg) 1.4.0, and possibly other versions before 1.5.0b1, allow remote attackers to execute arbitrary SQL commands via the (1) messageid, (2) shopper, (3) shopfor, or (4) itemid parameters."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"12289","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/12289"},{"name":"1012910","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1012910"},{"name":"phpgiftregistry-sql-injection(18925)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18925"},{"name":"20050307 Re: phpGiftReq SQL Injection","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/392485"},{"name":"13873","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/13873"},{"name":"20050116 phpGiftReq SQL Injection","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=110599710017066&w=2"},{"name":"20050116 phpGiftReq SQL Injection","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030965.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-0292","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple SQL injection vulnerabilities in index.php in PHP Gift Registry (phpGiftReg) 1.4.0, and possibly other versions before 1.5.0b1, allow remote attackers to execute arbitrary SQL commands via the (1) messageid, (2) shopper, (3) shopfor, or (4) itemid parameters."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"12289","refsource":"BID","url":"http://www.securityfocus.com/bid/12289"},{"name":"1012910","refsource":"SECTRACK","url":"http://securitytracker.com/id?1012910"},{"name":"phpgiftregistry-sql-injection(18925)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18925"},{"name":"20050307 Re: phpGiftReq SQL Injection","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/392485"},{"name":"13873","refsource":"SECUNIA","url":"http://secunia.com/advisories/13873"},{"name":"20050116 phpGiftReq SQL Injection","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=110599710017066&w=2"},{"name":"20050116 phpGiftReq SQL Injection","refsource":"FULLDISC","url":"http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030965.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-0292","datePublished":"2005-02-10T05:00:00.000Z","dateReserved":"2005-02-10T00:00:00.000Z","dateUpdated":"2024-08-07T21:05:25.474Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-01-17 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:php_gift_registry:phpgiftreg:1.4:*:*:*:*:*:*:*","matchCriteriaId":"4FF9E7E9-30E5-412C-8FC4-17151A3C9437"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"292","Ordinal":"1","Title":"CVE-2005-0292","CVE":"CVE-2005-0292","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"292","Ordinal":"1","NoteData":"Multiple SQL injection vulnerabilities in index.php in PHP Gift Registry (phpGiftReg) 1.4.0, and possibly other versions before 1.5.0b1, allow remote attackers to execute arbitrary SQL commands via the (1) messageid, (2) shopper, (3) shopfor, or (4) itemid parameters.","Type":"Description","Title":"CVE-2005-0292"},{"CveYear":"2005","CveId":"292","Ordinal":"2","NoteData":"2005-02-10","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"292","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}