{"api_version":"1","generated_at":"2026-07-23T09:16:53+00:00","cve":"CVE-2005-3309","urls":{"html":"https://cve.report/CVE-2005-3309","api":"https://cve.report/api/cve/CVE-2005-3309.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-3309","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-3309"},"summary":{"title":"CVE-2005-3309","description":"Multiple SQL injection vulnerabilities in Zomplog 3.4 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in detail.php and the catid parameter in (2) get.php and (3) index.php.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-10-26 01:02:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.osvdb.org/20251","name":"http://www.osvdb.org/20251","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://securitytracker.com/alerts/2005/Oct/1015088.html","name":"http://securitytracker.com/alerts/2005/Oct/1015088.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"SecurityTracker.com Archives - Zomplog Input Validation Holes Permit SQL Injection and Cross-Site Scripting Attacks","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/17306/","name":"http://secunia.com/advisories/17306/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - Zomplog Cross-Site Scripting and SQL Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/20252","name":"http://www.osvdb.org/20252","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22827","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22827","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/20250","name":"http://www.osvdb.org/20250","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-3309","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-3309","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"3309","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zomplog","cpe5":"zomplog","cpe6":"3.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T23:10:07.582Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20250","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/20250"},{"name":"20252","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/20252"},{"name":"20251","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/20251"},{"name":"1015088","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/alerts/2005/Oct/1015088.html"},{"name":"17306","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/17306/"},{"name":"zomplog-multiple-scripts-sql-injection(22827)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22827"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-10-22T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple SQL injection vulnerabilities in Zomplog 3.4 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in detail.php and the catid parameter in (2) get.php and (3) index.php."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20250","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/20250"},{"name":"20252","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/20252"},{"name":"20251","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/20251"},{"name":"1015088","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/alerts/2005/Oct/1015088.html"},{"name":"17306","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/17306/"},{"name":"zomplog-multiple-scripts-sql-injection(22827)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22827"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-3309","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple SQL injection vulnerabilities in Zomplog 3.4 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in detail.php and the catid parameter in (2) get.php and (3) index.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20250","refsource":"OSVDB","url":"http://www.osvdb.org/20250"},{"name":"20252","refsource":"OSVDB","url":"http://www.osvdb.org/20252"},{"name":"20251","refsource":"OSVDB","url":"http://www.osvdb.org/20251"},{"name":"1015088","refsource":"SECTRACK","url":"http://securitytracker.com/alerts/2005/Oct/1015088.html"},{"name":"17306","refsource":"SECUNIA","url":"http://secunia.com/advisories/17306/"},{"name":"zomplog-multiple-scripts-sql-injection(22827)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/22827"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-3309","datePublished":"2005-10-25T04:00:00.000Z","dateReserved":"2005-10-26T00:00:00.000Z","dateUpdated":"2024-08-07T23:10:07.582Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-10-26 01:02:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:zomplog:zomplog:3.4:*:*:*:*:*:*:*","matchCriteriaId":"A2B40804-E719-41D9-9AFF-B3AF3AC13DFC"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"3309","Ordinal":"1","Title":"CVE-2005-3309","CVE":"CVE-2005-3309","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"3309","Ordinal":"1","NoteData":"Multiple SQL injection vulnerabilities in Zomplog 3.4 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in detail.php and the catid parameter in (2) get.php and (3) index.php.","Type":"Description","Title":"CVE-2005-3309"},{"CveYear":"2005","CveId":"3309","Ordinal":"2","NoteData":"2005-10-25","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"3309","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}