{"api_version":"1","generated_at":"2026-07-23T07:09:35+00:00","cve":"CVE-2005-2113","urls":{"html":"https://cve.report/CVE-2005-2113","api":"https://cve.report/api/cve/CVE-2005-2113.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-2113","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-2113"},"summary":{"title":"CVE-2005-2113","description":"SQL injection vulnerability in the loginUser function in the XMLRPC server in XOOPS 2.0.11 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via crafted values in an XML file, as demonstrated using the blogger.getPost method.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-07-05 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://secunia.com/advisories/15843","name":"http://secunia.com/advisories/15843","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Secunia - Advisories - Xoops Cross-Site Scripting and SQL Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=112006318512991&w=2","name":"http://marc.info/?l=bugtraq&m=112006318512991&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'XOOPS 2.0.11 && Earlier Multiple Vulnerabilities' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.xoops.org/modules/news/article.php?storyid=2383","name":"http://www.xoops.org/modules/news/article.php?storyid=2383","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Security Release: XOOPS 2.0.12a - Security - XOOPS News - XOOPS Web Application System","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://www.gulftech.org/?node=research&article_id=00086-06292005","name":"http://www.gulftech.org/?node=research&article_id=00086-06292005","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Contact Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-2113","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-2113","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"2113","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xoops","cpe5":"xoops","cpe6":"2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"2113","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xoops","cpe5":"xoops","cpe6":"2.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"2113","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xoops","cpe5":"xoops","cpe6":"2.0.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"2113","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xoops","cpe5":"xoops","cpe6":"2.0.11","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"2113","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xoops","cpe5":"xoops","cpe6":"2.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"2113","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xoops","cpe5":"xoops","cpe6":"2.0.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"2113","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xoops","cpe5":"xoops","cpe6":"2.0.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"2113","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xoops","cpe5":"xoops","cpe6":"2.0.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"2113","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xoops","cpe5":"xoops","cpe6":"2.0.5.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"2113","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xoops","cpe5":"xoops","cpe6":"2.0.5.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"2113","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xoops","cpe5":"xoops","cpe6":"2.0.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"2113","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xoops","cpe5":"xoops","cpe6":"2.0.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"2113","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xoops","cpe5":"xoops","cpe6":"2.0.9","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"2113","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xoops","cpe5":"xoops","cpe6":"2.0.9.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"2113","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xoops","cpe5":"xoops","cpe6":"2.0.9.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T22:15:37.400Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20050629 XOOPS 2.0.11 && Earlier Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=112006318512991&w=2"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.gulftech.org/?node=research&article_id=00086-06292005"},{"name":"15843","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/15843"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.xoops.org/modules/news/article.php?storyid=2383"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-06-29T00:00:00.000Z","descriptions":[{"lang":"en","value":"SQL injection vulnerability in the loginUser function in the XMLRPC server in XOOPS 2.0.11 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via crafted values in an XML file, as demonstrated using the blogger.getPost method."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-10-17T13:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20050629 XOOPS 2.0.11 && Earlier Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=112006318512991&w=2"},{"tags":["x_refsource_MISC"],"url":"http://www.gulftech.org/?node=research&article_id=00086-06292005"},{"name":"15843","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/15843"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.xoops.org/modules/news/article.php?storyid=2383"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-2113","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"SQL injection vulnerability in the loginUser function in the XMLRPC server in XOOPS 2.0.11 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via crafted values in an XML file, as demonstrated using the blogger.getPost method."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20050629 XOOPS 2.0.11 && Earlier Multiple Vulnerabilities","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=112006318512991&w=2"},{"name":"http://www.gulftech.org/?node=research&article_id=00086-06292005","refsource":"MISC","url":"http://www.gulftech.org/?node=research&article_id=00086-06292005"},{"name":"15843","refsource":"SECUNIA","url":"http://secunia.com/advisories/15843"},{"name":"http://www.xoops.org/modules/news/article.php?storyid=2383","refsource":"CONFIRM","url":"http://www.xoops.org/modules/news/article.php?storyid=2383"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-2113","datePublished":"2005-07-01T04:00:00.000Z","dateReserved":"2005-07-01T00:00:00.000Z","dateUpdated":"2024-08-07T22:15:37.400Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-07-05 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:xoops:xoops:2.0:*:*:*:*:*:*:*","matchCriteriaId":"1D649637-9772-4B71-B219-DD505CDB3549"},{"vulnerable":true,"criteria":"cpe:2.3:a:xoops:xoops:2.0.1:*:*:*:*:*:*:*","matchCriteriaId":"33E91D0D-42F6-4FAC-BD04-AA4D77C6DAD3"},{"vulnerable":true,"criteria":"cpe:2.3:a:xoops:xoops:2.0.2:*:*:*:*:*:*:*","matchCriteriaId":"881DDA3C-4D95-471F-95BA-6C4629B3CB68"},{"vulnerable":true,"criteria":"cpe:2.3:a:xoops:xoops:2.0.3:*:*:*:*:*:*:*","matchCriteriaId":"E235D928-E2D9-46D3-B95F-C4AF556D3C01"},{"vulnerable":true,"criteria":"cpe:2.3:a:xoops:xoops:2.0.4:*:*:*:*:*:*:*","matchCriteriaId":"5F0B5583-8489-4AF9-AD04-4A56AC244A59"},{"vulnerable":true,"criteria":"cpe:2.3:a:xoops:xoops:2.0.5:*:*:*:*:*:*:*","matchCriteriaId":"0C32DECD-1E28-4CC1-812B-E8D54B5703EE"},{"vulnerable":true,"criteria":"cpe:2.3:a:xoops:xoops:2.0.5.1:*:*:*:*:*:*:*","matchCriteriaId":"9AD25BC1-E435-4691-B42A-0D98D80F0F83"},{"vulnerable":true,"criteria":"cpe:2.3:a:xoops:xoops:2.0.5.2:*:*:*:*:*:*:*","matchCriteriaId":"1F58A3E7-4C21-48FD-AA26-7CCE85BAE887"},{"vulnerable":true,"criteria":"cpe:2.3:a:xoops:xoops:2.0.6:*:*:*:*:*:*:*","matchCriteriaId":"26950415-06AF-4910-A881-121EA0B43058"},{"vulnerable":true,"criteria":"cpe:2.3:a:xoops:xoops:2.0.7:*:*:*:*:*:*:*","matchCriteriaId":"89CFFAD2-F511-431C-BF24-08CA810B4645"},{"vulnerable":true,"criteria":"cpe:2.3:a:xoops:xoops:2.0.9:*:*:*:*:*:*:*","matchCriteriaId":"675A7068-CE9E-412A-8159-2A3820D6272E"},{"vulnerable":true,"criteria":"cpe:2.3:a:xoops:xoops:2.0.9.2:*:*:*:*:*:*:*","matchCriteriaId":"FC857372-A76D-4F3D-9FEE-6086A0AB002C"},{"vulnerable":true,"criteria":"cpe:2.3:a:xoops:xoops:2.0.9.3:*:*:*:*:*:*:*","matchCriteriaId":"AA2D117B-2800-462A-BA58-E71AED33EEFA"},{"vulnerable":true,"criteria":"cpe:2.3:a:xoops:xoops:2.0.10:*:*:*:*:*:*:*","matchCriteriaId":"08729570-512B-4B7E-A055-B8E312F41E86"},{"vulnerable":true,"criteria":"cpe:2.3:a:xoops:xoops:2.0.11:*:*:*:*:*:*:*","matchCriteriaId":"476872A3-838B-40B7-B180-2FE018EA9BE1"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"2113","Ordinal":"1","Title":"CVE-2005-2113","CVE":"CVE-2005-2113","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"2113","Ordinal":"1","NoteData":"SQL injection vulnerability in the loginUser function in the XMLRPC server in XOOPS 2.0.11 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via crafted values in an XML file, as demonstrated using the blogger.getPost method.","Type":"Description","Title":"CVE-2005-2113"},{"CveYear":"2005","CveId":"2113","Ordinal":"2","NoteData":"2005-07-01","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"2113","Ordinal":"3","NoteData":"2016-10-17","Type":"Other","Title":"Modified"}]}}}