{"api_version":"1","generated_at":"2026-05-15T22:41:59+00:00","cve":"CVE-2005-1948","urls":{"html":"https://cve.report/CVE-2005-1948","api":"https://cve.report/api/cve/CVE-2005-1948.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-1948","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-1948"},"summary":{"title":"CVE-2005-1948","description":"Multiple SQL injection vulnerabilities in Invision Gallery before 1.3.1 allow remote attackers to execute arbitrary SQL commands via (1) the comment parameter in an editcomment action or (2) the rating parameter when voting on a photo.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-06-09 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.gulftech.org/?node=research&article_id=00079-06092005","name":"http://www.gulftech.org/?node=research&article_id=00079-06092005","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch","Vendor Advisory"],"title":"Contact Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/13907","name":"http://www.securityfocus.com/bid/13907","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Invision Power Services Invision Gallery SQL Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://marc.info/?l=bugtraq&m=111834146710329&w=2","name":"http://marc.info/?l=bugtraq&m=111834146710329&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'Invision Gallery Vulnerabilities' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-1948","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-1948","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"1948","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"invision_power_services","cpe5":"invision_gallery","cpe6":"1.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"1948","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"invision_power_services","cpe5":"invision_gallery","cpe6":"1.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T22:06:57.721Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.gulftech.org/?node=research&article_id=00079-06092005"},{"name":"13907","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/13907"},{"name":"20050609 Invision Gallery Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=111834146710329&w=2"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-06-09T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple SQL injection vulnerabilities in Invision Gallery before 1.3.1 allow remote attackers to execute arbitrary SQL commands via (1) the comment parameter in an editcomment action or (2) the rating parameter when voting on a photo."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-10-17T13:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://www.gulftech.org/?node=research&article_id=00079-06092005"},{"name":"13907","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/13907"},{"name":"20050609 Invision Gallery Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=111834146710329&w=2"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-1948","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple SQL injection vulnerabilities in Invision Gallery before 1.3.1 allow remote attackers to execute arbitrary SQL commands via (1) the comment parameter in an editcomment action or (2) the rating parameter when voting on a photo."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.gulftech.org/?node=research&article_id=00079-06092005","refsource":"MISC","url":"http://www.gulftech.org/?node=research&article_id=00079-06092005"},{"name":"13907","refsource":"BID","url":"http://www.securityfocus.com/bid/13907"},{"name":"20050609 Invision Gallery Vulnerabilities","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=111834146710329&w=2"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-1948","datePublished":"2005-06-14T04:00:00.000Z","dateReserved":"2005-06-14T00:00:00.000Z","dateUpdated":"2024-08-07T22:06:57.721Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-06-09 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:invision_power_services:invision_gallery:1.0.1:*:*:*:*:*:*:*","matchCriteriaId":"9CA45453-5C5F-4730-9343-01CAF0F84705"},{"vulnerable":true,"criteria":"cpe:2.3:a:invision_power_services:invision_gallery:1.3:*:*:*:*:*:*:*","matchCriteriaId":"4DB69839-3DBF-4C69-94F9-A482A683C641"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"1948","Ordinal":"1","Title":"CVE-2005-1948","CVE":"CVE-2005-1948","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"1948","Ordinal":"1","NoteData":"Multiple SQL injection vulnerabilities in Invision Gallery before 1.3.1 allow remote attackers to execute arbitrary SQL commands via (1) the comment parameter in an editcomment action or (2) the rating parameter when voting on a photo.","Type":"Description","Title":"CVE-2005-1948"},{"CveYear":"2005","CveId":"1948","Ordinal":"2","NoteData":"2005-06-14","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"1948","Ordinal":"3","NoteData":"2016-10-17","Type":"Other","Title":"Modified"}]}}}