{"api_version":"1","generated_at":"2026-07-23T06:56:49+00:00","cve":"CVE-2005-3209","urls":{"html":"https://cve.report/CVE-2005-3209","api":"https://cve.report/api/cve/CVE-2005-3209.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-3209","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-3209"},"summary":{"title":"CVE-2005-3209","description":"Aenovo products (1) aeNovo, (2) aeNovoShop, and (3) aeNovoWYSI store password information in plaintext in the (a) control, (b) content, and (c) page tables, which allows attackers with database access to obtain those passwords and gain privileges.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-10-14 10:02:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.6","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.kapda.ir/advisory-78.html","name":"http://www.kapda.ir/advisory-78.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"KAPDA :: Aenovo SQL_Injection & XSS","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=112872593432359&w=2","name":"http://marc.info/?l=bugtraq&m=112872593432359&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'Aenovo Multiple Vulnerabilities' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22549","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22549","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/17117/","name":"http://secunia.com/advisories/17117/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - aeNovo Cross-Site Scripting and SQL Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/19939","name":"http://www.osvdb.org/19939","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-3209","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-3209","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"3209","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"aenovo","cpe5":"aenovo","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"3209","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"aenovo","cpe5":"aenovoshop","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"3209","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"aenovo","cpe5":"aenovowysi","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T23:01:59.065Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"17117","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/17117/"},{"name":"20051007 Aenovo Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=112872593432359&w=2"},{"name":"aenovo-password-information-disclosure(22549)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22549"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.kapda.ir/advisory-78.html"},{"name":"19939","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/19939"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-10-07T00:00:00.000Z","descriptions":[{"lang":"en","value":"Aenovo products (1) aeNovo, (2) aeNovoShop, and (3) aeNovoWYSI store password information in plaintext in the (a) control, (b) content, and (c) page tables, which allows attackers with database access to obtain those passwords and gain privileges."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"17117","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/17117/"},{"name":"20051007 Aenovo Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=112872593432359&w=2"},{"name":"aenovo-password-information-disclosure(22549)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22549"},{"tags":["x_refsource_MISC"],"url":"http://www.kapda.ir/advisory-78.html"},{"name":"19939","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/19939"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-3209","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Aenovo products (1) aeNovo, (2) aeNovoShop, and (3) aeNovoWYSI store password information in plaintext in the (a) control, (b) content, and (c) page tables, which allows attackers with database access to obtain those passwords and gain privileges."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"17117","refsource":"SECUNIA","url":"http://secunia.com/advisories/17117/"},{"name":"20051007 Aenovo Multiple Vulnerabilities","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=112872593432359&w=2"},{"name":"aenovo-password-information-disclosure(22549)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22549"},{"name":"http://www.kapda.ir/advisory-78.html","refsource":"MISC","url":"http://www.kapda.ir/advisory-78.html"},{"name":"19939","refsource":"OSVDB","url":"http://www.osvdb.org/19939"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-3209","datePublished":"2005-10-14T04:00:00.000Z","dateReserved":"2005-10-14T00:00:00.000Z","dateUpdated":"2024-08-07T23:01:59.065Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-10-14 10:02:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":true,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:aenovo:aenovo:*:*:*:*:*:*:*:*","matchCriteriaId":"C0CA4376-FB7C-4FB3-AF36-E28907CB6A46"},{"vulnerable":true,"criteria":"cpe:2.3:a:aenovo:aenovoshop:*:*:*:*:*:*:*:*","matchCriteriaId":"3E84793B-F90B-440D-B6DD-4F9F1D4EC431"},{"vulnerable":true,"criteria":"cpe:2.3:a:aenovo:aenovowysi:*:*:*:*:*:*:*:*","matchCriteriaId":"A66F6D79-0C97-4458-921C-48AECE03973A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"3209","Ordinal":"1","Title":"CVE-2005-3209","CVE":"CVE-2005-3209","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"3209","Ordinal":"1","NoteData":"Aenovo products (1) aeNovo, (2) aeNovoShop, and (3) aeNovoWYSI store password information in plaintext in the (a) control, (b) content, and (c) page tables, which allows attackers with database access to obtain those passwords and gain privileges.","Type":"Description","Title":"CVE-2005-3209"},{"CveYear":"2005","CveId":"3209","Ordinal":"2","NoteData":"2005-10-14","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"3209","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}