CVE-2005-4232

critical

Description

SQL injection vulnerability in index.php in Jamit Job Board 2.4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: the vendor has disputed this issue, saying "The vulnerability is without any basis and did not actually work." CVE has not verified either the vendor or researcher statements, but the original researcher is known to make frequent mistakes when reporting SQL injection

References

http://www.vupen.com/english/advisories/2005/2879

http://www.securityfocus.com/bid/15848

http://www.osvdb.org/21687

http://www.attrition.org/pipermail/vim/2006-August/000972.html

http://secunia.com/advisories/18007

http://pridels0.blogspot.com/2005/12/jamit-job-board-24x-sql-inj.html

Details

Source: Mitre, NVD

Published: 2005-12-14

Updated: 2026-06-16

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.00484