CVE-2005-3309

critical

Description

Multiple SQL injection vulnerabilities in Zomplog 3.4 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in detail.php and the catid parameter in (2) get.php and (3) index.php.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/22827

http://www.osvdb.org/20252

http://www.osvdb.org/20251

http://www.osvdb.org/20250

http://secunia.com/advisories/17306/

Details

Source: Mitre, NVD

Published: 2005-10-26

Updated: 2026-06-16

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.00963