{"api_version":"1","generated_at":"2026-07-23T09:02:44+00:00","cve":"CVE-2005-4478","urls":{"html":"https://cve.report/CVE-2005-4478","api":"https://cve.report/api/cve/CVE-2005-4478.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-4478","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-4478"},"summary":{"title":"CVE-2005-4478","description":"Multiple SQL injection vulnerabilities in Papoo 2.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) menuid parameter to (a) index.php and (b) guestbook.php, and the (2) forumid and (3) reporeid_print parameters to (c) print.php.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-12-22 11:03:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["CWE-89","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/bid/16020","name":"http://www.securityfocus.com/bid/16020","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Papoo Multiple SQL Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.osvdb.org/displayvuln.php?osvdb_id=21871","name":"http://www.osvdb.org/displayvuln.php?osvdb_id=21871","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/18152","name":"http://secunia.com/advisories/18152","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Papoo SQL Injection Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/21869","name":"http://www.osvdb.org/21869","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2005/3046","name":"http://www.vupen.com/english/advisories/2005/3046","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/displayvuln.php?osvdb_id=21870","name":"http://www.osvdb.org/displayvuln.php?osvdb_id=21870","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://pridels0.blogspot.com/2005/12/papoo-multiple-sql-vuln.html","name":"http://pridels0.blogspot.com/2005/12/papoo-multiple-sql-vuln.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"- UNSECURED SYSTEMS -: Papoo Multiple SQL vuln.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-4478","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-4478","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"4478","vulnerable":"1","versionEndIncluding":"2.1.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"papoo","cpe5":"papoo","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T23:46:05.540Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"18152","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/18152"},{"name":"16020","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/16020"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://pridels0.blogspot.com/2005/12/papoo-multiple-sql-vuln.html"},{"name":"21869","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/21869"},{"name":"ADV-2005-3046","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2005/3046"},{"name":"21871","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/displayvuln.php?osvdb_id=21871"},{"name":"21870","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/displayvuln.php?osvdb_id=21870"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-12-21T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple SQL injection vulnerabilities in Papoo 2.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) menuid parameter to (a) index.php and (b) guestbook.php, and the (2) forumid and (3) reporeid_print parameters to (c) print.php."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2007-09-13T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"18152","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/18152"},{"name":"16020","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/16020"},{"tags":["x_refsource_MISC"],"url":"http://pridels0.blogspot.com/2005/12/papoo-multiple-sql-vuln.html"},{"name":"21869","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/21869"},{"name":"ADV-2005-3046","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2005/3046"},{"name":"21871","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/displayvuln.php?osvdb_id=21871"},{"name":"21870","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/displayvuln.php?osvdb_id=21870"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-4478","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple SQL injection vulnerabilities in Papoo 2.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) menuid parameter to (a) index.php and (b) guestbook.php, and the (2) forumid and (3) reporeid_print parameters to (c) print.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"18152","refsource":"SECUNIA","url":"http://secunia.com/advisories/18152"},{"name":"16020","refsource":"BID","url":"http://www.securityfocus.com/bid/16020"},{"name":"http://pridels0.blogspot.com/2005/12/papoo-multiple-sql-vuln.html","refsource":"MISC","url":"http://pridels0.blogspot.com/2005/12/papoo-multiple-sql-vuln.html"},{"name":"21869","refsource":"OSVDB","url":"http://www.osvdb.org/21869"},{"name":"ADV-2005-3046","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2005/3046"},{"name":"21871","refsource":"OSVDB","url":"http://www.osvdb.org/displayvuln.php?osvdb_id=21871"},{"name":"21870","refsource":"OSVDB","url":"http://www.osvdb.org/displayvuln.php?osvdb_id=21870"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-4478","datePublished":"2005-12-22T11:00:00.000Z","dateReserved":"2005-12-22T00:00:00.000Z","dateUpdated":"2024-08-07T23:46:05.540Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-12-22 11:03:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["CWE-89","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:papoo:papoo:*:*:*:*:*:*:*:*","versionEndIncluding":"2.1.2","matchCriteriaId":"971FF217-A1E4-4564-9AF0-302D273C78F1"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"4478","Ordinal":"1","Title":"CVE-2005-4478","CVE":"CVE-2005-4478","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"4478","Ordinal":"1","NoteData":"Multiple SQL injection vulnerabilities in Papoo 2.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) menuid parameter to (a) index.php and (b) guestbook.php, and the (2) forumid and (3) reporeid_print parameters to (c) print.php.","Type":"Description","Title":"CVE-2005-4478"},{"CveYear":"2005","CveId":"4478","Ordinal":"2","NoteData":"2005-12-22","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"4478","Ordinal":"3","NoteData":"2007-09-13","Type":"Other","Title":"Modified"}]}}}