{"api_version":"1","generated_at":"2026-07-23T03:24:26+00:00","cve":"CVE-2005-4232","urls":{"html":"https://cve.report/CVE-2005-4232","api":"https://cve.report/api/cve/CVE-2005-4232.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-4232","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-4232"},"summary":{"title":"CVE-2005-4232","description":"SQL injection vulnerability in index.php in Jamit Job Board 2.4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter.  NOTE: the vendor has disputed this issue, saying \"The vulnerability is without any basis and did not actually work.\" CVE has not verified either the vendor or researcher statements, but the original researcher is known to make frequent mistakes when reporting SQL injection","state":"PUBLISHED","assigner":"mitre","published_at":"2005-12-14 11:03:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["CWE-89","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2005/2879","name":"http://www.vupen.com/english/advisories/2005/2879","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://pridels0.blogspot.com/2005/12/jamit-job-board-24x-sql-inj.html","name":"http://pridels0.blogspot.com/2005/12/jamit-job-board-24x-sql-inj.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"- UNSECURED SYSTEMS -: Jamit Job Board 2.4.x SQL inj.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/15848","name":"http://www.securityfocus.com/bid/15848","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Jamit Job Board Index.PHP SQL Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/18007","name":"http://secunia.com/advisories/18007","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Jamit Job Board \"cat\" SQL Injection Vulnerability - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.attrition.org/pipermail/vim/2006-August/000972.html","name":"http://www.attrition.org/pipermail/vim/2006-August/000972.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[VIM] vendor dispute: 21687: Jamit Job Board index.php cat Variable SQL Injection (fwd)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/21687","name":"http://www.osvdb.org/21687","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-4232","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-4232","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"4232","vulnerable":"1","versionEndIncluding":"2.4.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"jamit","cpe5":"jamit_job_board","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T23:38:51.687Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"21687","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/21687"},{"name":"15848","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/15848"},{"name":"18007","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/18007"},{"name":"ADV-2005-2879","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2005/2879"},{"name":"20060814 vendor dispute: 21687: Jamit Job Board index.php cat Variable SQL Injection (fwd)","tags":["mailing-list","x_refsource_VIM","x_transferred"],"url":"http://www.attrition.org/pipermail/vim/2006-August/000972.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://pridels0.blogspot.com/2005/12/jamit-job-board-24x-sql-inj.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-12-14T00:00:00.000Z","descriptions":[{"lang":"en","value":"SQL injection vulnerability in index.php in Jamit Job Board 2.4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter.  NOTE: the vendor has disputed this issue, saying \"The vulnerability is without any basis and did not actually work.\" CVE has not verified either the vendor or researcher statements, but the original researcher is known to make frequent mistakes when reporting SQL injection"}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2005-12-20T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"21687","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/21687"},{"name":"15848","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/15848"},{"name":"18007","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/18007"},{"name":"ADV-2005-2879","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2005/2879"},{"name":"20060814 vendor dispute: 21687: Jamit Job Board index.php cat Variable SQL Injection (fwd)","tags":["mailing-list","x_refsource_VIM"],"url":"http://www.attrition.org/pipermail/vim/2006-August/000972.html"},{"tags":["x_refsource_MISC"],"url":"http://pridels0.blogspot.com/2005/12/jamit-job-board-24x-sql-inj.html"}],"tags":["disputed"],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-4232","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"** DISPUTED **  SQL injection vulnerability in index.php in Jamit Job Board 2.4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter.  NOTE: the vendor has disputed this issue, saying \"The vulnerability is without any basis and did not actually work.\" CVE has not verified either the vendor or researcher statements, but the original researcher is known to make frequent mistakes when reporting SQL injection."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"21687","refsource":"OSVDB","url":"http://www.osvdb.org/21687"},{"name":"15848","refsource":"BID","url":"http://www.securityfocus.com/bid/15848"},{"name":"18007","refsource":"SECUNIA","url":"http://secunia.com/advisories/18007"},{"name":"ADV-2005-2879","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2005/2879"},{"name":"20060814 vendor dispute: 21687: Jamit Job Board index.php cat Variable SQL Injection (fwd)","refsource":"VIM","url":"http://www.attrition.org/pipermail/vim/2006-August/000972.html"},{"name":"http://pridels0.blogspot.com/2005/12/jamit-job-board-24x-sql-inj.html","refsource":"MISC","url":"http://pridels0.blogspot.com/2005/12/jamit-job-board-24x-sql-inj.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-4232","datePublished":"2005-12-14T11:00:00.000Z","dateReserved":"2005-12-14T00:00:00.000Z","dateUpdated":"2024-08-07T23:38:51.687Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-12-14 11:03:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["CWE-89","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:jamit:jamit_job_board:*:*:*:*:*:*:*:*","versionEndIncluding":"2.4.1","matchCriteriaId":"B4651FCA-21C2-4200-B68B-B055D98F17AB"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"4232","Ordinal":"1","Title":"CVE-2005-4232","CVE":"CVE-2005-4232","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"4232","Ordinal":"1","NoteData":"SQL injection vulnerability in index.php in Jamit Job Board 2.4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter.  NOTE: the vendor has disputed this issue, saying \"The vulnerability is without any basis and did not actually work.\" CVE has not verified either the vendor or researcher statements, but the original researcher is known to make frequent mistakes when reporting SQL injection","Type":"Description","Title":"CVE-2005-4232"},{"CveYear":"2005","CveId":"4232","Ordinal":"2","NoteData":"2005-12-14","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"4232","Ordinal":"3","NoteData":"2005-12-20","Type":"Other","Title":"Modified"}]}}}