CVE-2005-4135
Estado: ModificadaAlta (7.5)—
Direct static code injection vulnerability in includes/newtopic.php in SimpleBBS 1.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the Host header (possibly the name parameter or variable), which is then written to data/topics.php.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 8.62%
- Percentil entre todas las CVEs puntuadas: 95
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://secunia.com/advisories/17949
- http://securitytracker.com/id?1015323
- http://www.securityfocus.com/archive/1/418838/100/0/threaded
- http://www.securityfocus.com/bid/15764
- http://www.vupen.com/english/advisories/2005/2807
- http://secunia.com/advisories/17949
- http://securitytracker.com/id?1015323
- http://www.securityfocus.com/archive/1/418838/100/0/threaded
- http://www.securityfocus.com/bid/15764
- http://www.vupen.com/english/advisories/2005/2807
JSON original (NVD)
Mostrar
{
"id": "CVE-2005-4135",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": true,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2005-12-09T15:03:00.000",
"references": [
{
"url": "http://secunia.com/advisories/17949",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://securitytracker.com/id?1015323",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/418838/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/15764",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2005/2807",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/17949",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securitytracker.com/id?1015323",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/418838/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/15764",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2005/2807",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Direct static code injection vulnerability in includes/newtopic.php in SimpleBBS 1.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the Host header (possibly the name parameter or variable), which is then written to data/topics.php."
}
],
"lastModified": "2026-06-16T22:18:14.233",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:simplemedia:simplebbs:1.0.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3C22A112-E9E0-4480-9406-9F685D577F98"
},
{
"criteria": "cpe:2.3:a:simplemedia:simplebbs:1.0.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5D4ED99C-AFBA-485A-BDCC-A43C781F1DA2"
},
{
"criteria": "cpe:2.3:a:simplemedia:simplebbs:1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "04CFC80A-2F70-4B73-AFDA-C1A524274381"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}