{"api_version":"1","generated_at":"2026-07-23T06:20:24+00:00","cve":"CVE-2005-0569","urls":{"html":"https://cve.report/CVE-2005-0569","api":"https://cve.report/api/cve/CVE-2005-0569.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-0569","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-0569"},"summary":{"title":"CVE-2005-0569","description":"Multiple SQL injection vulnerabilities in PunBB 1.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) language parameter to register.php, (2) change email feature in profile.php, (3) posts or (4) topics parameter to moderate.php.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-05-02 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.punbb.org/changelogs/1.2.1_to_1.2.2.txt","name":"http://www.punbb.org/changelogs/1.2.1_to_1.2.2.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/plain","httpstatus":"-1","archivestatus":"200"},{"url":"http://secunia.com/advisories/14394","name":"http://secunia.com/advisories/14394","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Secunia - Advisories - PunBB Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/19473","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/19473","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=110927754230666&w=2","name":"http://marc.info/?l=bugtraq&m=110927754230666&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'Multiple vulns in punBB' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/14538","name":"http://secunia.com/advisories/14538","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Secunia - Advisories - BLOG:CMS PunBB SQL Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/12652","name":"http://www.securityfocus.com/bid/12652","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch"],"title":"PunBB Multiple Remote Input Validation Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-0569","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-0569","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"569","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"punbb","cpe5":"punbb","cpe6":"1.2.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T21:21:05.694Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"14538","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/14538"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.punbb.org/changelogs/1.2.1_to_1.2.2.txt"},{"name":"punbb-multiple-sql-injection(19473)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/19473"},{"name":"12652","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/12652"},{"name":"14394","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/14394"},{"name":"20050224 Multiple vulns in punBB","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=110927754230666&w=2"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-02-24T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple SQL injection vulnerabilities in PunBB 1.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) language parameter to register.php, (2) change email feature in profile.php, (3) posts or (4) topics parameter to moderate.php."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"14538","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/14538"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.punbb.org/changelogs/1.2.1_to_1.2.2.txt"},{"name":"punbb-multiple-sql-injection(19473)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/19473"},{"name":"12652","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/12652"},{"name":"14394","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/14394"},{"name":"20050224 Multiple vulns in punBB","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=110927754230666&w=2"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-0569","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple SQL injection vulnerabilities in PunBB 1.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) language parameter to register.php, (2) change email feature in profile.php, (3) posts or (4) topics parameter to moderate.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"14538","refsource":"SECUNIA","url":"http://secunia.com/advisories/14538"},{"name":"http://www.punbb.org/changelogs/1.2.1_to_1.2.2.txt","refsource":"CONFIRM","url":"http://www.punbb.org/changelogs/1.2.1_to_1.2.2.txt"},{"name":"punbb-multiple-sql-injection(19473)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/19473"},{"name":"12652","refsource":"BID","url":"http://www.securityfocus.com/bid/12652"},{"name":"14394","refsource":"SECUNIA","url":"http://secunia.com/advisories/14394"},{"name":"20050224 Multiple vulns in punBB","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=110927754230666&w=2"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-0569","datePublished":"2005-02-27T05:00:00.000Z","dateReserved":"2005-02-27T00:00:00.000Z","dateUpdated":"2024-08-07T21:21:05.694Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-05-02 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:punbb:punbb:1.2.1:*:*:*:*:*:*:*","matchCriteriaId":"05BCF8A0-5530-4B36-8CEA-5330307C74CC"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"569","Ordinal":"1","Title":"CVE-2005-0569","CVE":"CVE-2005-0569","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"569","Ordinal":"1","NoteData":"Multiple SQL injection vulnerabilities in PunBB 1.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) language parameter to register.php, (2) change email feature in profile.php, (3) posts or (4) topics parameter to moderate.php.","Type":"Description","Title":"CVE-2005-0569"},{"CveYear":"2005","CveId":"569","Ordinal":"2","NoteData":"2005-02-27","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"569","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}