CVE-2005-4232
Estado: ModificadaAlta (7.5)—
SQL injection vulnerability in index.php in Jamit Job Board 2.4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: the vendor has disputed this issue, saying "The vulnerability is without any basis and did not actually work." CVE has not verified either the vendor or researcher statements, but the original researcher is known to make frequent mistakes when reporting SQL injection
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.21%
- Percentil entre todas las CVEs puntuadas: 67
- Fecha de la puntuación: 3/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-89
Referencias
- http://pridels0.blogspot.com/2005/12/jamit-job-board-24x-sql-inj.html
- http://secunia.com/advisories/18007
- http://www.attrition.org/pipermail/vim/2006-August/000972.html
- http://www.osvdb.org/21687
- http://www.securityfocus.com/bid/15848
- http://www.vupen.com/english/advisories/2005/2879
- http://pridels0.blogspot.com/2005/12/jamit-job-board-24x-sql-inj.html
- http://secunia.com/advisories/18007
- http://www.attrition.org/pipermail/vim/2006-August/000972.html
- http://www.osvdb.org/21687
- http://www.securityfocus.com/bid/15848
- http://www.vupen.com/english/advisories/2005/2879
JSON original (NVD)
Mostrar
{
"id": "CVE-2005-4232",
"cveTags": [
{
"tags": [
"disputed"
],
"sourceIdentifier": "cve@mitre.org"
}
],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2005-12-14T11:03:00.000",
"references": [
{
"url": "http://pridels0.blogspot.com/2005/12/jamit-job-board-24x-sql-inj.html",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/18007",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.attrition.org/pipermail/vim/2006-August/000972.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/21687",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/15848",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2005/2879",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://pridels0.blogspot.com/2005/12/jamit-job-board-24x-sql-inj.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/18007",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.attrition.org/pipermail/vim/2006-August/000972.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/21687",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/15848",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2005/2879",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "SQL injection vulnerability in index.php in Jamit Job Board 2.4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: the vendor has disputed this issue, saying \"The vulnerability is without any basis and did not actually work.\" CVE has not verified either the vendor or researcher statements, but the original researcher is known to make frequent mistakes when reporting SQL injection"
}
],
"lastModified": "2026-06-16T22:18:24.417",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:jamit:jamit_job_board:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B4651FCA-21C2-4200-B68B-B055D98F17AB",
"versionEndIncluding": "2.4.1"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}