{"api_version":"1","generated_at":"2026-07-23T14:20:31+00:00","cve":"CVE-2005-3816","urls":{"html":"https://cve.report/CVE-2005-3816","api":"https://cve.report/api/cve/CVE-2005-3816.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-3816","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-3816"},"summary":{"title":"CVE-2005-3816","description":"Multiple SQL injection vulnerabilities in forum.php in freeForum 1.1 and earlier and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter or (2) thread parameter in thread mode.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-11-26 02:03:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://securitytracker.com/id?1015269","name":"http://securitytracker.com/id?1015269","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - freeForum Input Validation Flaw in 'cat' and 'thread' Parameters Permits SQL Injection Attacks","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/17720","name":"http://secunia.com/advisories/17720","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - freeForum \"thread\" SQL Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/15559","name":"http://www.securityfocus.com/bid/15559","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"FreeForum Multiple SQL Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2005/2571","name":"http://www.vupen.com/english/advisories/2005/2571","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/21086","name":"http://www.osvdb.org/21086","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://pridels0.blogspot.com/2005/11/freeforum-1x-cat-and-thread-sql-inj.html","name":"http://pridels0.blogspot.com/2005/11/freeforum-1x-cat-and-thread-sql-inj.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"- UNSECURED SYSTEMS -: freeForum 1.x \"cat\"  and \"thread\" SQL inj.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-3816","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-3816","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"3816","vulnerable":"1","versionEndIncluding":"1.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zoneo-soft","cpe5":"freeforum","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T23:24:36.347Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"1015269","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1015269"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://pridels0.blogspot.com/2005/11/freeforum-1x-cat-and-thread-sql-inj.html"},{"name":"ADV-2005-2571","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2005/2571"},{"name":"21086","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/21086"},{"name":"17720","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/17720"},{"name":"15559","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/15559"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-11-23T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple SQL injection vulnerabilities in forum.php in freeForum 1.1 and earlier and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter or (2) thread parameter in thread mode."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2005-12-01T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"1015269","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1015269"},{"tags":["x_refsource_MISC"],"url":"http://pridels0.blogspot.com/2005/11/freeforum-1x-cat-and-thread-sql-inj.html"},{"name":"ADV-2005-2571","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2005/2571"},{"name":"21086","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/21086"},{"name":"17720","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/17720"},{"name":"15559","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/15559"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-3816","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple SQL injection vulnerabilities in forum.php in freeForum 1.1 and earlier and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter or (2) thread parameter in thread mode."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1015269","refsource":"SECTRACK","url":"http://securitytracker.com/id?1015269"},{"name":"http://pridels0.blogspot.com/2005/11/freeforum-1x-cat-and-thread-sql-inj.html","refsource":"MISC","url":"http://pridels0.blogspot.com/2005/11/freeforum-1x-cat-and-thread-sql-inj.html"},{"name":"ADV-2005-2571","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2005/2571"},{"name":"21086","refsource":"OSVDB","url":"http://www.osvdb.org/21086"},{"name":"17720","refsource":"SECUNIA","url":"http://secunia.com/advisories/17720"},{"name":"15559","refsource":"BID","url":"http://www.securityfocus.com/bid/15559"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-3816","datePublished":"2005-11-26T02:00:00.000Z","dateReserved":"2005-11-26T00:00:00.000Z","dateUpdated":"2024-08-07T23:24:36.347Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-11-26 02:03:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:zoneo-soft:freeforum:*:*:*:*:*:*:*:*","versionEndIncluding":"1.1","matchCriteriaId":"599F223E-AB55-4FB9-9DA5-2E2C9D10B477"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"3816","Ordinal":"1","Title":"CVE-2005-3816","CVE":"CVE-2005-3816","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"3816","Ordinal":"1","NoteData":"Multiple SQL injection vulnerabilities in forum.php in freeForum 1.1 and earlier and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter or (2) thread parameter in thread mode.","Type":"Description","Title":"CVE-2005-3816"},{"CveYear":"2005","CveId":"3816","Ordinal":"2","NoteData":"2005-11-25","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"3816","Ordinal":"3","NoteData":"2005-12-01","Type":"Other","Title":"Modified"}]}}}