CVE-2005-2473
Multiple SQL injection vulnerabilities in ChurchInfo allow remote attackers to execute arbitrary SQL commands via the PersonID parameter to (1) PersonView.php, (2) MemberRoleChange.php, (3) PropertyAssign.php, (4) WhyCameEditor.php, (5) GroupPropsEditor.php, (6) Reports/PDFLabel.php, or (7) UserDelete.php, (8) DepositSlipID parameter to DepositSlipEditor.php, (9) QueryID parameter to QueryView.php, GroupID parameter to (10) GroupView.php, (11) GroupMemberList.php, (12) MemberRoleChange.php, (13) GroupDelete.php, (14) /Reports/ClassAttendance.php, or (15) /Reports/GroupReport.php, (16) PropertyID parameter to PropertyEditor.php, FamilyID parameter to (17) Canvas05Editor.php, (18) CanvasEditor.php, or (19) FamilyView.php, or (20) PledgeID parameter to PledgeDetails.php.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Base score: 7.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 2.01%
- Percentile among all scored CVEs: 80
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- NVD-CWE-Other
References
- http://marc.info/?l=bugtraq&m=112291550713546&w=2
- http://secunia.com/advisories/16292
- http://securitytracker.com/id?1014617
- http://www.osvdb.org/18408
- http://www.osvdb.org/18409
- http://www.osvdb.org/18410
- http://www.osvdb.org/18411
- http://www.osvdb.org/18412
- http://www.osvdb.org/18413
- http://www.osvdb.org/18414
- http://www.osvdb.org/18415
- http://www.osvdb.org/18416
- http://www.osvdb.org/18417
- http://www.osvdb.org/18418
- http://www.osvdb.org/18419
- http://www.osvdb.org/18420
- http://www.osvdb.org/18421
- http://www.osvdb.org/18422
- http://www.osvdb.org/18423
- http://www.osvdb.org/18424
- http://www.osvdb.org/18427
- http://www.osvdb.org/18428
- http://www.securityfocus.com/bid/14438
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21647
- http://marc.info/?l=bugtraq&m=112291550713546&w=2
- http://secunia.com/advisories/16292
- http://securitytracker.com/id?1014617
- http://www.osvdb.org/18408
- http://www.osvdb.org/18409
- http://www.osvdb.org/18410
- http://www.osvdb.org/18411
- http://www.osvdb.org/18412
- http://www.osvdb.org/18413
- http://www.osvdb.org/18414
- http://www.osvdb.org/18415
- http://www.osvdb.org/18416
- http://www.osvdb.org/18417
- http://www.osvdb.org/18418
- http://www.osvdb.org/18419
- http://www.osvdb.org/18420
- http://www.osvdb.org/18421
- http://www.osvdb.org/18422
- http://www.osvdb.org/18423
- http://www.osvdb.org/18424
- http://www.osvdb.org/18427
- http://www.osvdb.org/18428
- http://www.securityfocus.com/bid/14438
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21647
Raw JSON (NVD)
Show
{
"id": "CVE-2005-2473",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2005-08-05T04:00:00.000",
"references": [
{
"url": "http://marc.info/?l=bugtraq&m=112291550713546&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/16292",
"source": "cve@mitre.org"
},
{
"url": "http://securitytracker.com/id?1014617",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/18408",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/18409",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/18410",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/18411",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/18412",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/18413",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/18414",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/18415",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/18416",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/18417",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/18418",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/18419",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/18420",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/18421",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/18422",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/18423",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/18424",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/18427",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/18428",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/14438",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/21647",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=112291550713546&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/16292",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securitytracker.com/id?1014617",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/18408",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/18409",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/18410",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/18411",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/18412",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/18413",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/18414",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/18415",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/18416",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/18417",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/18418",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/18419",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/18420",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/18421",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/18422",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/18423",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/18424",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/18427",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/18428",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/14438",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/21647",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple SQL injection vulnerabilities in ChurchInfo allow remote attackers to execute arbitrary SQL commands via the PersonID parameter to (1) PersonView.php, (2) MemberRoleChange.php, (3) PropertyAssign.php, (4) WhyCameEditor.php, (5) GroupPropsEditor.php, (6) Reports/PDFLabel.php, or (7) UserDelete.php, (8) DepositSlipID parameter to DepositSlipEditor.php, (9) QueryID parameter to QueryView.php, GroupID parameter to (10) GroupView.php, (11) GroupMemberList.php, (12) MemberRoleChange.php, (13) GroupDelete.php, (14) /Reports/ClassAttendance.php, or (15) /Reports/GroupReport.php, (16) PropertyID parameter to PropertyEditor.php, FamilyID parameter to (17) Canvas05Editor.php, (18) CanvasEditor.php, or (19) FamilyView.php, or (20) PledgeID parameter to PledgeDetails.php."
},
{
"lang": "es",
"value": "Múltiples vulnerabilidades de inyección de SQL en ChurchInfo permite que atacantes remotos ejecuten comandos SQL arbitrarios en: (1) PersonView.php, (2) MemberRoleChange.php, (3) PropertyAssign.php, (4) WhyCameEditor.php, (5) GroupPropsEditor.php, (6) Reports/PDFLabel.php, (7) UserDelete.php, (8) DepositSlipEditor.php, (9) QueryView.php, (10) GroupView.php, (11) GroupMemberList.php, (12) MemberRoleChange.php, (13) GroupDelete.php, (14) /Reports/ClassAttendance.php, (15) /Reports/GroupReport.php, (16) PropertyEditor.php, (17) Canvas05Editor.php, (18) CanvasEditor.php, (19) FamilyView.php, (20) PledgeDetails.php."
}
],
"lastModified": "2026-06-16T22:14:57.480",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:churchinfo:churchinfo:1.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F879219C-C632-459D-A16F-8342B60462A8"
},
{
"criteria": "cpe:2.3:a:churchinfo:churchinfo:1.1.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C1C82088-3340-4612-BA6A-86A7F8E960F4"
},
{
"criteria": "cpe:2.3:a:churchinfo:churchinfo:1.1.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E8C458ED-C5A0-4F6F-874D-7736BC9B4DF6"
},
{
"criteria": "cpe:2.3:a:churchinfo:churchinfo:1.1.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DBB7A122-18F3-4EC2-B91F-17F3D18C4B95"
},
{
"criteria": "cpe:2.3:a:churchinfo:churchinfo:1.1.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "24D3103F-8660-481E-8B6A-6BEC565E668C"
},
{
"criteria": "cpe:2.3:a:churchinfo:churchinfo:1.1.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8DD7E63B-9E84-4C73-B6B9-97E19F763AC9"
},
{
"criteria": "cpe:2.3:a:churchinfo:churchinfo:1.2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "62AF3C4E-031D-4F81-94F2-11FF29BF2207"
},
{
"criteria": "cpe:2.3:a:churchinfo:churchinfo:1.2.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "78C41826-6116-4F37-BA73-6B9C8AE2A299"
},
{
"criteria": "cpe:2.3:a:churchinfo:churchinfo:1.2.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D1F6567B-558F-475D-8EC4-9067F4F643DA"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}