{"api_version":"1","generated_at":"2026-07-23T05:24:07+00:00","cve":"CVE-2005-3208","urls":{"html":"https://cve.report/CVE-2005-3208","api":"https://cve.report/api/cve/CVE-2005-3208.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-3208","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-3208"},"summary":{"title":"CVE-2005-3208","description":"Multiple SQL injection vulnerabilities in (1) aeNovo, (2) aeNovoShop and (3) aeNovoWYSI allow remote attackers to execute arbitrary SQL code via (a) the password parameter in control.asp, and (b) the strSQL parameter in search.asp, which can enable XSS attacks in resulting error messages.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-10-14 10:02:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.osvdb.org/19936","name":"http://www.osvdb.org/19936","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.kapda.ir/advisory-78.html","name":"http://www.kapda.ir/advisory-78.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"KAPDA :: Aenovo SQL_Injection & XSS","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22551","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22551","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22553","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22553","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=112872593432359&w=2","name":"http://marc.info/?l=bugtraq&m=112872593432359&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'Aenovo Multiple Vulnerabilities' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22547","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22547","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/17117/","name":"http://secunia.com/advisories/17117/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - aeNovo Cross-Site Scripting and SQL Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/15038","name":"http://www.securityfocus.com/bid/15038","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Aenovo Multiple Unspecified Cross-Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/15036","name":"http://www.securityfocus.com/bid/15036","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Aenovo Multiple SQL Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.osvdb.org/19937","name":"http://www.osvdb.org/19937","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-3208","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-3208","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"3208","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"aenovo","cpe5":"aenovo","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"3208","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"aenovo","cpe5":"aenovoshop","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"3208","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"aenovo","cpe5":"aenovowysi","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T23:01:59.064Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"17117","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/17117/"},{"name":"19936","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/19936"},{"name":"15036","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/15036"},{"name":"20051007 Aenovo Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=112872593432359&w=2"},{"name":"aenovo-xss(22553)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22553"},{"name":"aenovo-strsql-sql-injection(22551)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22551"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.kapda.ir/advisory-78.html"},{"name":"15038","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/15038"},{"name":"aenovo-password-sql-injection(22547)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22547"},{"name":"19937","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/19937"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-10-07T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple SQL injection vulnerabilities in (1) aeNovo, (2) aeNovoShop and (3) aeNovoWYSI allow remote attackers to execute arbitrary SQL code via (a) the password parameter in control.asp, and (b) the strSQL parameter in search.asp, which can enable XSS attacks in resulting error messages."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"17117","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/17117/"},{"name":"19936","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/19936"},{"name":"15036","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/15036"},{"name":"20051007 Aenovo Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=112872593432359&w=2"},{"name":"aenovo-xss(22553)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22553"},{"name":"aenovo-strsql-sql-injection(22551)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22551"},{"tags":["x_refsource_MISC"],"url":"http://www.kapda.ir/advisory-78.html"},{"name":"15038","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/15038"},{"name":"aenovo-password-sql-injection(22547)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22547"},{"name":"19937","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/19937"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-3208","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple SQL injection vulnerabilities in (1) aeNovo, (2) aeNovoShop and (3) aeNovoWYSI allow remote attackers to execute arbitrary SQL code via (a) the password parameter in control.asp, and (b) the strSQL parameter in search.asp, which can enable XSS attacks in resulting error messages."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"17117","refsource":"SECUNIA","url":"http://secunia.com/advisories/17117/"},{"name":"19936","refsource":"OSVDB","url":"http://www.osvdb.org/19936"},{"name":"15036","refsource":"BID","url":"http://www.securityfocus.com/bid/15036"},{"name":"20051007 Aenovo Multiple Vulnerabilities","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=112872593432359&w=2"},{"name":"aenovo-xss(22553)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22553"},{"name":"aenovo-strsql-sql-injection(22551)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22551"},{"name":"http://www.kapda.ir/advisory-78.html","refsource":"MISC","url":"http://www.kapda.ir/advisory-78.html"},{"name":"15038","refsource":"BID","url":"http://www.securityfocus.com/bid/15038"},{"name":"aenovo-password-sql-injection(22547)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22547"},{"name":"19937","refsource":"OSVDB","url":"http://www.osvdb.org/19937"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-3208","datePublished":"2005-10-14T04:00:00.000Z","dateReserved":"2005-10-14T00:00:00.000Z","dateUpdated":"2024-08-07T23:01:59.064Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-10-14 10:02:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:aenovo:aenovo:*:*:*:*:*:*:*:*","matchCriteriaId":"C0CA4376-FB7C-4FB3-AF36-E28907CB6A46"},{"vulnerable":true,"criteria":"cpe:2.3:a:aenovo:aenovoshop:*:*:*:*:*:*:*:*","matchCriteriaId":"3E84793B-F90B-440D-B6DD-4F9F1D4EC431"},{"vulnerable":true,"criteria":"cpe:2.3:a:aenovo:aenovowysi:*:*:*:*:*:*:*:*","matchCriteriaId":"A66F6D79-0C97-4458-921C-48AECE03973A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"3208","Ordinal":"1","Title":"CVE-2005-3208","CVE":"CVE-2005-3208","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"3208","Ordinal":"1","NoteData":"Multiple SQL injection vulnerabilities in (1) aeNovo, (2) aeNovoShop and (3) aeNovoWYSI allow remote attackers to execute arbitrary SQL code via (a) the password parameter in control.asp, and (b) the strSQL parameter in search.asp, which can enable XSS attacks in resulting error messages.","Type":"Description","Title":"CVE-2005-3208"},{"CveYear":"2005","CveId":"3208","Ordinal":"2","NoteData":"2005-10-14","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"3208","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}