{"api_version":"1","generated_at":"2026-07-23T09:19:54+00:00","cve":"CVE-2005-3838","urls":{"html":"https://cve.report/CVE-2005-3838","api":"https://cve.report/api/cve/CVE-2005-3838.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-3838","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-3838"},"summary":{"title":"CVE-2005-3838","description":"Multiple SQL injection vulnerabilities in search.php in IsolSoft Support Center 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) lorder, (2) Priority, (3) Status, (4) Category, (5) searchvalue, and (6) field parameter.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-11-26 22:03:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/bid/15570","name":"http://www.securityfocus.com/bid/15570","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"IsolSoft Support Center Multiple SQL Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://pridels0.blogspot.com/2005/11/isolsoft-support-center-sql-inj.html","name":"http://pridels0.blogspot.com/2005/11/isolsoft-support-center-sql-inj.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"- UNSECURED SYSTEMS -: IsolSoft Support Center SQL inj.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/17728","name":"http://secunia.com/advisories/17728","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"IsolSoft Support Center SQL Injection Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2005/2592","name":"http://www.vupen.com/english/advisories/2005/2592","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/21102","name":"http://www.osvdb.org/21102","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://securitytracker.com/id?1015270","name":"http://securitytracker.com/id?1015270","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"SecurityTracker.com Archives - IsolSoft Support Center Input Validation Holes in 'search.php' Permit SQL Injection Attacks","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-3838","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-3838","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"3838","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"isolsoft","cpe5":"support_center","cpe6":"2.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T23:24:36.507Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"1015270","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1015270"},{"name":"15570","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/15570"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://pridels0.blogspot.com/2005/11/isolsoft-support-center-sql-inj.html"},{"name":"21102","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/21102"},{"name":"17728","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/17728"},{"name":"ADV-2005-2592","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2005/2592"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-11-24T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple SQL injection vulnerabilities in search.php in IsolSoft Support Center 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) lorder, (2) Priority, (3) Status, (4) Category, (5) searchvalue, and (6) field parameter."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2005-12-01T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"1015270","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1015270"},{"name":"15570","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/15570"},{"tags":["x_refsource_MISC"],"url":"http://pridels0.blogspot.com/2005/11/isolsoft-support-center-sql-inj.html"},{"name":"21102","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/21102"},{"name":"17728","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/17728"},{"name":"ADV-2005-2592","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2005/2592"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-3838","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple SQL injection vulnerabilities in search.php in IsolSoft Support Center 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) lorder, (2) Priority, (3) Status, (4) Category, (5) searchvalue, and (6) field parameter."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1015270","refsource":"SECTRACK","url":"http://securitytracker.com/id?1015270"},{"name":"15570","refsource":"BID","url":"http://www.securityfocus.com/bid/15570"},{"name":"http://pridels0.blogspot.com/2005/11/isolsoft-support-center-sql-inj.html","refsource":"MISC","url":"http://pridels0.blogspot.com/2005/11/isolsoft-support-center-sql-inj.html"},{"name":"21102","refsource":"OSVDB","url":"http://www.osvdb.org/21102"},{"name":"17728","refsource":"SECUNIA","url":"http://secunia.com/advisories/17728"},{"name":"ADV-2005-2592","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2005/2592"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-3838","datePublished":"2005-11-26T22:00:00.000Z","dateReserved":"2005-11-26T00:00:00.000Z","dateUpdated":"2024-08-07T23:24:36.507Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-11-26 22:03:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:isolsoft:support_center:2.2:*:*:*:*:*:*:*","matchCriteriaId":"3F3872C4-3A91-4998-BCFE-B9AA24C37B96"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"3838","Ordinal":"1","Title":"CVE-2005-3838","CVE":"CVE-2005-3838","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"3838","Ordinal":"1","NoteData":"Multiple SQL injection vulnerabilities in search.php in IsolSoft Support Center 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) lorder, (2) Priority, (3) Status, (4) Category, (5) searchvalue, and (6) field parameter.","Type":"Description","Title":"CVE-2005-3838"},{"CveYear":"2005","CveId":"3838","Ordinal":"2","NoteData":"2005-11-26","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"3838","Ordinal":"3","NoteData":"2005-12-01","Type":"Other","Title":"Modified"}]}}}