{"api_version":"1","generated_at":"2026-07-23T08:47:19+00:00","cve":"CVE-2005-0375","urls":{"html":"https://cve.report/CVE-2005-0375","api":"https://cve.report/api/cve/CVE-2005-0375.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-0375","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-0375"},"summary":{"title":"CVE-2005-0375","description":"imageview.php in SGallery 1.01 allows remote attackers to obtain sensitive information via an HTTP request with (1) idalbum and (2) idimage unset, which reveals the installation path in an error message for the sql_fetch_row function.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-05-02 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://marc.info/?l=bugtraq&m=110557050700947&w=2","name":"http://marc.info/?l=bugtraq&m=110557050700947&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'[waraxe-2005-SA#039] - Critical Sql Injection in Sgallery module' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18877","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18877","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.waraxe.us/advisory-39.html","name":"http://www.waraxe.us/advisory-39.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"Waraxe IT Security Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030844.html","name":"http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030844.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[Full-Disclosure] [waraxe-2005-SA#039] - Critical Sql Injection in\n\tSgallery module for PhpNuke","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://securitytracker.com/id?1012868","name":"http://securitytracker.com/id?1012868","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - SGallery Input Validation Holes Let Remote Users Inject SQL Commands and Potentially Execute Arbitrary Commands","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-0375","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-0375","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"375","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sergey_kiselev","cpe5":"sgallery","cpe6":"1.01","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T21:13:53.526Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20050112 [waraxe-2005-SA#039] - Critical Sql Injection in Sgallery module for PhpNuke","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=110557050700947&w=2"},{"name":"20050112 [waraxe-2005-SA#039] - Critical Sql Injection in Sgallery module for PhpNuke","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030844.html"},{"name":"sgallery-path-disclosure(18877)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18877"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.waraxe.us/advisory-39.html"},{"name":"1012868","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1012868"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-01-12T00:00:00.000Z","descriptions":[{"lang":"en","value":"imageview.php in SGallery 1.01 allows remote attackers to obtain sensitive information via an HTTP request with (1) idalbum and (2) idimage unset, which reveals the installation path in an error message for the sql_fetch_row function."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20050112 [waraxe-2005-SA#039] - Critical Sql Injection in Sgallery module for PhpNuke","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=110557050700947&w=2"},{"name":"20050112 [waraxe-2005-SA#039] - Critical Sql Injection in Sgallery module for PhpNuke","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030844.html"},{"name":"sgallery-path-disclosure(18877)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18877"},{"tags":["x_refsource_MISC"],"url":"http://www.waraxe.us/advisory-39.html"},{"name":"1012868","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1012868"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-0375","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"imageview.php in SGallery 1.01 allows remote attackers to obtain sensitive information via an HTTP request with (1) idalbum and (2) idimage unset, which reveals the installation path in an error message for the sql_fetch_row function."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20050112 [waraxe-2005-SA#039] - Critical Sql Injection in Sgallery module for PhpNuke","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=110557050700947&w=2"},{"name":"20050112 [waraxe-2005-SA#039] - Critical Sql Injection in Sgallery module for PhpNuke","refsource":"FULLDISC","url":"http://lists.grok.org.uk/pipermail/full-disclosure/2005-January/030844.html"},{"name":"sgallery-path-disclosure(18877)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18877"},{"name":"http://www.waraxe.us/advisory-39.html","refsource":"MISC","url":"http://www.waraxe.us/advisory-39.html"},{"name":"1012868","refsource":"SECTRACK","url":"http://securitytracker.com/id?1012868"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-0375","datePublished":"2005-02-13T05:00:00.000Z","dateReserved":"2005-02-13T00:00:00.000Z","dateUpdated":"2024-08-07T21:13:53.526Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-05-02 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:sergey_kiselev:sgallery:1.01:*:*:*:*:*:*:*","matchCriteriaId":"EAE5AE46-E927-46C7-AFBF-A27432D96D15"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"375","Ordinal":"1","Title":"CVE-2005-0375","CVE":"CVE-2005-0375","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"375","Ordinal":"1","NoteData":"imageview.php in SGallery 1.01 allows remote attackers to obtain sensitive information via an HTTP request with (1) idalbum and (2) idimage unset, which reveals the installation path in an error message for the sql_fetch_row function.","Type":"Description","Title":"CVE-2005-0375"},{"CveYear":"2005","CveId":"375","Ordinal":"2","NoteData":"2005-02-13","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"375","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}