{"api_version":"1","generated_at":"2026-07-23T06:42:16+00:00","cve":"CVE-2005-3937","urls":{"html":"https://cve.report/CVE-2005-3937","api":"https://cve.report/api/cve/CVE-2005-3937.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-3937","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-3937"},"summary":{"title":"CVE-2005-3937","description":"SQL injection vulnerability in Softbiz B2B Trading Marketplace Script 1.1 and earler allows remote attackers to execute arbitrary SQL commands via the cid parameter in (1) selloffers.php, (2) buyoffers.php, (3) products.php, or (4) profiles.php.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-12-01 06:03:00","updated_at":"2026-04-06 14:41:30"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.osvdb.org/21252","name":"http://www.osvdb.org/21252","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/15652","name":"http://www.securityfocus.com/bid/15652","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Softbiz B2B Trading Marketplace Multiple SQL Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.osvdb.org/21254","name":"http://www.osvdb.org/21254","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://pridels0.blogspot.com/2005/11/softbiz-b2b-trading-marketplace-script.html","name":"http://pridels0.blogspot.com/2005/11/softbiz-b2b-trading-marketplace-script.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"- UNSECURED SYSTEMS -: Softbiz B2B trading Marketplace Script SQL inj.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/21255","name":"http://www.osvdb.org/21255","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/17808","name":"http://secunia.com/advisories/17808","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Secunia - Advisories - Softbiz B2B Trading Marketplace Script \"cid\" SQL Injection","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/21253","name":"http://www.osvdb.org/21253","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-3937","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-3937","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"3937","vulnerable":"1","versionEndIncluding":"1.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"softbizscripts","cpe5":"b2b_trading_marketplace_script","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2005","cve_id":"3937","cve":"CVE-2005-3937","epss":"0.008210000","percentile":"0.743650000","score_date":"2026-04-07","updated_at":"2026-04-08 00:03:39"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T23:31:48.647Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"21254","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/21254"},{"name":"15652","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/15652"},{"name":"21252","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/21252"},{"name":"17808","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/17808"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://pridels0.blogspot.com/2005/11/softbiz-b2b-trading-marketplace-script.html"},{"name":"21255","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/21255"},{"name":"21253","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/21253"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-11-28T00:00:00.000Z","descriptions":[{"lang":"en","value":"SQL injection vulnerability in Softbiz B2B Trading Marketplace Script 1.1 and earler allows remote attackers to execute arbitrary SQL commands via the cid parameter in (1) selloffers.php, (2) buyoffers.php, (3) products.php, or (4) profiles.php."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2005-12-08T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"21254","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/21254"},{"name":"15652","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/15652"},{"name":"21252","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/21252"},{"name":"17808","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/17808"},{"tags":["x_refsource_MISC"],"url":"http://pridels0.blogspot.com/2005/11/softbiz-b2b-trading-marketplace-script.html"},{"name":"21255","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/21255"},{"name":"21253","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/21253"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-3937","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"SQL injection vulnerability in Softbiz B2B Trading Marketplace Script 1.1 and earler allows remote attackers to execute arbitrary SQL commands via the cid parameter in (1) selloffers.php, (2) buyoffers.php, (3) products.php, or (4) profiles.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"21254","refsource":"OSVDB","url":"http://www.osvdb.org/21254"},{"name":"15652","refsource":"BID","url":"http://www.securityfocus.com/bid/15652"},{"name":"21252","refsource":"OSVDB","url":"http://www.osvdb.org/21252"},{"name":"17808","refsource":"SECUNIA","url":"http://secunia.com/advisories/17808"},{"name":"http://pridels0.blogspot.com/2005/11/softbiz-b2b-trading-marketplace-script.html","refsource":"MISC","url":"http://pridels0.blogspot.com/2005/11/softbiz-b2b-trading-marketplace-script.html"},{"name":"21255","refsource":"OSVDB","url":"http://www.osvdb.org/21255"},{"name":"21253","refsource":"OSVDB","url":"http://www.osvdb.org/21253"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-3937","datePublished":"2005-12-01T11:00:00.000Z","dateReserved":"2005-12-01T00:00:00.000Z","dateUpdated":"2024-08-07T23:31:48.647Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-12-01 06:03:00","lastModifiedDate":"2026-04-06 14:41:30","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:softbizscripts:b2b_trading_marketplace_script:*:*:*:*:*:*:*:*","versionEndIncluding":"1.1","matchCriteriaId":"B05DC23B-09C1-479C-9651-966C0168930A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"3937","Ordinal":"1","Title":"CVE-2005-3937","CVE":"CVE-2005-3937","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"3937","Ordinal":"1","NoteData":"SQL injection vulnerability in Softbiz B2B Trading Marketplace Script 1.1 and earler allows remote attackers to execute arbitrary SQL commands via the cid parameter in (1) selloffers.php, (2) buyoffers.php, (3) products.php, or (4) profiles.php.","Type":"Description","Title":"CVE-2005-3937"},{"CveYear":"2005","CveId":"3937","Ordinal":"2","NoteData":"2005-12-01","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"3937","Ordinal":"3","NoteData":"2005-12-08","Type":"Other","Title":"Modified"}]}}}