{"api_version":"1","generated_at":"2026-07-23T06:56:35+00:00","cve":"CVE-2005-2415","urls":{"html":"https://cve.report/CVE-2005-2415","api":"https://cve.report/api/cve/CVE-2005-2415.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-2415","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-2415"},"summary":{"title":"CVE-2005-2415","description":"Multiple SQL injection vulnerabilities in Contrexx before 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) value parameter to the poll module or (2) pId parameter to the gallery module.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-08-03 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21482","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21482","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/16169","name":"http://secunia.com/advisories/16169","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Contrexx CMS Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/14352","name":"http://www.securityfocus.com/bid/14352","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Contrexx Multiple Input Validation Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.osvdb.org/18167","name":"http://www.osvdb.org/18167","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://marc.info/?l=bugtraq&m=112206702015439&w=2","name":"http://marc.info/?l=bugtraq&m=112206702015439&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'Advisory 11/2005: Multiple vulnerabilities in Contrexx' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.hardened-php.net/advisory_112005.59.html","name":"http://www.hardened-php.net/advisory_112005.59.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch","Vendor Advisory"],"title":"Hardened-PHP Project - PHP Security\n\n      - Advisory 11/2005","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/18166","name":"http://www.osvdb.org/18166","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://securitytracker.com/id?1014554","name":"http://securitytracker.com/id?1014554","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Contrexx Input Validation Holes Permit SQL Injection and Cross-Site Scripting Attacks","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-2415","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-2415","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"2415","vulnerable":"1","versionEndIncluding":"1.0.4","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"astalavista_it_engineering","cpe5":"contrexx","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T22:22:49.133Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"1014554","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1014554"},{"name":"16169","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/16169"},{"name":"20050722 Advisory 11/2005: Multiple vulnerabilities in Contrexx","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=112206702015439&w=2"},{"name":"14352","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/14352"},{"name":"18166","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/18166"},{"name":"contrexx-votingoption-pld-sql-injection(21482)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21482"},{"name":"18167","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/18167"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.hardened-php.net/advisory_112005.59.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-07-22T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple SQL injection vulnerabilities in Contrexx before 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) value parameter to the poll module or (2) pId parameter to the gallery module."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"1014554","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1014554"},{"name":"16169","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/16169"},{"name":"20050722 Advisory 11/2005: Multiple vulnerabilities in Contrexx","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=112206702015439&w=2"},{"name":"14352","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/14352"},{"name":"18166","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/18166"},{"name":"contrexx-votingoption-pld-sql-injection(21482)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21482"},{"name":"18167","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/18167"},{"tags":["x_refsource_MISC"],"url":"http://www.hardened-php.net/advisory_112005.59.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-2415","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple SQL injection vulnerabilities in Contrexx before 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) value parameter to the poll module or (2) pId parameter to the gallery module."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1014554","refsource":"SECTRACK","url":"http://securitytracker.com/id?1014554"},{"name":"16169","refsource":"SECUNIA","url":"http://secunia.com/advisories/16169"},{"name":"20050722 Advisory 11/2005: Multiple vulnerabilities in Contrexx","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=112206702015439&w=2"},{"name":"14352","refsource":"BID","url":"http://www.securityfocus.com/bid/14352"},{"name":"18166","refsource":"OSVDB","url":"http://www.osvdb.org/18166"},{"name":"contrexx-votingoption-pld-sql-injection(21482)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21482"},{"name":"18167","refsource":"OSVDB","url":"http://www.osvdb.org/18167"},{"name":"http://www.hardened-php.net/advisory_112005.59.html","refsource":"MISC","url":"http://www.hardened-php.net/advisory_112005.59.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-2415","datePublished":"2005-08-03T04:00:00.000Z","dateReserved":"2005-08-03T00:00:00.000Z","dateUpdated":"2024-08-07T22:22:49.133Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-08-03 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:astalavista_it_engineering:contrexx:*:*:*:*:*:*:*:*","versionEndIncluding":"1.0.4","matchCriteriaId":"3B18553E-DB63-4EB4-96AC-FA93E9F11B7A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"2415","Ordinal":"1","Title":"CVE-2005-2415","CVE":"CVE-2005-2415","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"2415","Ordinal":"1","NoteData":"Multiple SQL injection vulnerabilities in Contrexx before 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) value parameter to the poll module or (2) pId parameter to the gallery module.","Type":"Description","Title":"CVE-2005-2415"},{"CveYear":"2005","CveId":"2415","Ordinal":"2","NoteData":"2005-08-03","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"2415","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}