{"api_version":"1","generated_at":"2026-07-23T05:43:09+00:00","cve":"CVE-2005-3868","urls":{"html":"https://cve.report/CVE-2005-3868","api":"https://cve.report/api/cve/CVE-2005-3868.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-3868","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-3868"},"summary":{"title":"CVE-2005-3868","description":"Multiple SQL injection vulnerabilities in K-Search 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) term, (2) id, (3) stat, and (4) source parameters to index.php, and (5) through the image parameters with an add request.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-11-29 11:03:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://secunia.com/advisories/17719","name":"http://secunia.com/advisories/17719","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"K-Search SQL Injection and Cross-Site Scripting Vulnerabilities - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/15588","name":"http://www.securityfocus.com/bid/15588","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"K-Search SQL Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.osvdb.org/21127","name":"http://www.osvdb.org/21127","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2005/2616","name":"http://www.vupen.com/english/advisories/2005/2616","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://pridels0.blogspot.com/2005/11/k-search-multiple-vuln.html","name":"http://pridels0.blogspot.com/2005/11/k-search-multiple-vuln.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"- UNSECURED SYSTEMS -: K-Search Multiple vuln.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.exploit-db.com/exploits/13993","name":"http://www.exploit-db.com/exploits/13993","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"K-Search (SQL/XSS) Multiple Remote Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-3868","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-3868","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"3868","vulnerable":"1","versionEndIncluding":"1.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"turn-k","cpe5":"k-search","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T23:24:36.594Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2005-2616","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2005/2616"},{"name":"15588","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/15588"},{"name":"21127","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/21127"},{"name":"13993","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"http://www.exploit-db.com/exploits/13993"},{"name":"17719","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/17719"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://pridels0.blogspot.com/2005/11/k-search-multiple-vuln.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-11-28T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple SQL injection vulnerabilities in K-Search 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) term, (2) id, (3) stat, and (4) source parameters to index.php, and (5) through the image parameters with an add request."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2006-04-04T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ADV-2005-2616","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2005/2616"},{"name":"15588","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/15588"},{"name":"21127","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/21127"},{"name":"13993","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"http://www.exploit-db.com/exploits/13993"},{"name":"17719","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/17719"},{"tags":["x_refsource_MISC"],"url":"http://pridels0.blogspot.com/2005/11/k-search-multiple-vuln.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-3868","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple SQL injection vulnerabilities in K-Search 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) term, (2) id, (3) stat, and (4) source parameters to index.php, and (5) through the image parameters with an add request."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2005-2616","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2005/2616"},{"name":"15588","refsource":"BID","url":"http://www.securityfocus.com/bid/15588"},{"name":"21127","refsource":"OSVDB","url":"http://www.osvdb.org/21127"},{"name":"13993","refsource":"EXPLOIT-DB","url":"http://www.exploit-db.com/exploits/13993"},{"name":"17719","refsource":"SECUNIA","url":"http://secunia.com/advisories/17719"},{"name":"http://pridels0.blogspot.com/2005/11/k-search-multiple-vuln.html","refsource":"MISC","url":"http://pridels0.blogspot.com/2005/11/k-search-multiple-vuln.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-3868","datePublished":"2005-11-29T11:00:00.000Z","dateReserved":"2005-11-29T00:00:00.000Z","dateUpdated":"2024-08-07T23:24:36.594Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-11-29 11:03:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:turn-k:k-search:*:*:*:*:*:*:*:*","versionEndIncluding":"1.0","matchCriteriaId":"1FF37738-CE6B-4223-A31D-5A1FA9D6A1E3"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"3868","Ordinal":"1","Title":"CVE-2005-3868","CVE":"CVE-2005-3868","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"3868","Ordinal":"1","NoteData":"Multiple SQL injection vulnerabilities in K-Search 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) term, (2) id, (3) stat, and (4) source parameters to index.php, and (5) through the image parameters with an add request.","Type":"Description","Title":"CVE-2005-3868"},{"CveYear":"2005","CveId":"3868","Ordinal":"2","NoteData":"2005-11-29","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"3868","Ordinal":"3","NoteData":"2006-04-04","Type":"Other","Title":"Modified"}]}}}