{"api_version":"1","generated_at":"2026-07-23T11:35:49+00:00","cve":"CVE-2005-4251","urls":{"html":"https://cve.report/CVE-2005-4251","api":"https://cve.report/api/cve/CVE-2005-4251.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-4251","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-4251"},"summary":{"title":"CVE-2005-4251","description":"Multiple SQL injection vulnerabilities in mcGallery PRO 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) start, and (3) rand parameters to show.php, and the (4) album parameter to index.php.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-12-14 11:03:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/bid/15845","name":"http://www.securityfocus.com/bid/15845","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"mcGallery PRO Multiple Input Validation Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.osvdb.org/21719","name":"http://www.osvdb.org/21719","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.osvdb.org/21720","name":"http://www.osvdb.org/21720","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2005/2886","name":"http://www.vupen.com/english/advisories/2005/2886","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/18039","name":"http://secunia.com/advisories/18039","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Secunia - Advisories - mcGalleryPRO Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://pridels0.blogspot.com/2005/12/mcgallery-pro-vuln.html","name":"http://pridels0.blogspot.com/2005/12/mcgallery-pro-vuln.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"- UNSECURED SYSTEMS -: mcGallery PRO vuln.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-4251","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-4251","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"4251","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mcgallery","cpe5":"mcgallery_pro","cpe6":"1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"4251","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mcgallery","cpe5":"mcgallery_pro","cpe6":"1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"4251","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mcgallery","cpe5":"mcgallery_pro","cpe6":"2.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T23:38:51.560Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://pridels0.blogspot.com/2005/12/mcgallery-pro-vuln.html"},{"name":"21719","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/21719"},{"name":"18039","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/18039"},{"name":"15845","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/15845"},{"name":"21720","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/21720"},{"name":"ADV-2005-2886","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2005/2886"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-12-13T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple SQL injection vulnerabilities in mcGallery PRO 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) start, and (3) rand parameters to show.php, and the (4) album parameter to index.php."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2005-12-20T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://pridels0.blogspot.com/2005/12/mcgallery-pro-vuln.html"},{"name":"21719","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/21719"},{"name":"18039","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/18039"},{"name":"15845","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/15845"},{"name":"21720","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/21720"},{"name":"ADV-2005-2886","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2005/2886"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-4251","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple SQL injection vulnerabilities in mcGallery PRO 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) start, and (3) rand parameters to show.php, and the (4) album parameter to index.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://pridels0.blogspot.com/2005/12/mcgallery-pro-vuln.html","refsource":"MISC","url":"http://pridels0.blogspot.com/2005/12/mcgallery-pro-vuln.html"},{"name":"21719","refsource":"OSVDB","url":"http://www.osvdb.org/21719"},{"name":"18039","refsource":"SECUNIA","url":"http://secunia.com/advisories/18039"},{"name":"15845","refsource":"BID","url":"http://www.securityfocus.com/bid/15845"},{"name":"21720","refsource":"OSVDB","url":"http://www.osvdb.org/21720"},{"name":"ADV-2005-2886","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2005/2886"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-4251","datePublished":"2005-12-14T11:00:00.000Z","dateReserved":"2005-12-14T00:00:00.000Z","dateUpdated":"2024-08-07T23:38:51.560Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-12-14 11:03:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mcgallery:mcgallery_pro:1.0:*:*:*:*:*:*:*","matchCriteriaId":"85BF15CB-A95F-4475-8EE9-1F4FBC6DCABA"},{"vulnerable":true,"criteria":"cpe:2.3:a:mcgallery:mcgallery_pro:1.1:*:*:*:*:*:*:*","matchCriteriaId":"AFBBBF42-A2D8-4E5A-96B6-7688EBD1E6E2"},{"vulnerable":true,"criteria":"cpe:2.3:a:mcgallery:mcgallery_pro:2.2:*:*:*:*:*:*:*","matchCriteriaId":"CC6205CB-2B7E-4A77-A3BB-04FD69199C81"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"4251","Ordinal":"1","Title":"CVE-2005-4251","CVE":"CVE-2005-4251","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"4251","Ordinal":"1","NoteData":"Multiple SQL injection vulnerabilities in mcGallery PRO 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) start, and (3) rand parameters to show.php, and the (4) album parameter to index.php.","Type":"Description","Title":"CVE-2005-4251"},{"CveYear":"2005","CveId":"4251","Ordinal":"2","NoteData":"2005-12-14","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"4251","Ordinal":"3","NoteData":"2005-12-20","Type":"Other","Title":"Modified"}]}}}