{"api_version":"1","generated_at":"2026-07-23T07:14:57+00:00","cve":"CVE-2005-2637","urls":{"html":"https://cve.report/CVE-2005-2637","api":"https://cve.report/api/cve/CVE-2005-2637.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-2637","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-2637"},"summary":{"title":"CVE-2005-2637","description":"Multiple SQL injection vulnerabilities in PHPFreeNews 1.40 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) Match or (2) CatID parameter to SearchResults.php, or (3) the password to AccessControl.php.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-08-23 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://marc.info/?l=bugtraq&m=112439254700016&w=2","name":"http://marc.info/?l=bugtraq&m=112439254700016&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'PHPFreeNews V1.40 and prior Multiple Vulnerabilities' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/16490/","name":"http://secunia.com/advisories/16490/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - PHPFreeNews SQL Injection and Cross-Site Scripting","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/14589","name":"http://www.securityfocus.com/bid/14589","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"PHPFreeNews SearchResults.PHP Multiple SQL Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://securitytracker.com/id?1014726","name":"http://securitytracker.com/id?1014726","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - PHPFreeNews Input Validation Bugs in 'SearchResults.php' Permits SQL Injection and Cross-Site Scripting Attacks","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-2637","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-2637","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"2637","vulnerable":"1","versionEndIncluding":"1.40","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpfreenews","cpe5":"phpfreenews","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T22:45:00.945Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"16490","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/16490/"},{"name":"1014726","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1014726"},{"name":"20050817 PHPFreeNews V1.40 and prior Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=112439254700016&w=2"},{"name":"14589","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/14589"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-08-17T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple SQL injection vulnerabilities in PHPFreeNews 1.40 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) Match or (2) CatID parameter to SearchResults.php, or (3) the password to AccessControl.php."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-10-17T13:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"16490","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/16490/"},{"name":"1014726","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1014726"},{"name":"20050817 PHPFreeNews V1.40 and prior Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=112439254700016&w=2"},{"name":"14589","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/14589"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-2637","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple SQL injection vulnerabilities in PHPFreeNews 1.40 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) Match or (2) CatID parameter to SearchResults.php, or (3) the password to AccessControl.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"16490","refsource":"SECUNIA","url":"http://secunia.com/advisories/16490/"},{"name":"1014726","refsource":"SECTRACK","url":"http://securitytracker.com/id?1014726"},{"name":"20050817 PHPFreeNews V1.40 and prior Multiple Vulnerabilities","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=112439254700016&w=2"},{"name":"14589","refsource":"BID","url":"http://www.securityfocus.com/bid/14589"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-2637","datePublished":"2005-08-20T04:00:00.000Z","dateReserved":"2005-08-20T00:00:00.000Z","dateUpdated":"2024-08-07T22:45:00.945Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-08-23 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:phpfreenews:phpfreenews:*:*:*:*:*:*:*:*","versionEndIncluding":"1.40","matchCriteriaId":"76F4CC7D-3AF9-4E40-ACE4-51D8999F91F2"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"2637","Ordinal":"1","Title":"CVE-2005-2637","CVE":"CVE-2005-2637","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"2637","Ordinal":"1","NoteData":"Multiple SQL injection vulnerabilities in PHPFreeNews 1.40 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) Match or (2) CatID parameter to SearchResults.php, or (3) the password to AccessControl.php.","Type":"Description","Title":"CVE-2005-2637"},{"CveYear":"2005","CveId":"2637","Ordinal":"2","NoteData":"2005-08-20","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"2637","Ordinal":"3","NoteData":"2016-10-17","Type":"Other","Title":"Modified"}]}}}