Back

CVE-2005-0805

SQL injection vulnerability in index.php in Subdreamer Light, when magic_quotes_gpc is enabled, allows remote attackers to execute arbitrary SQL commands via certain parameters that are used as global variables, as demonstrated using the imageid parameter, which is not properly handled by imagegallery.php.

Published: May 2, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
subdreamer subdreamer_light 1.0

GitHub Security Advisory GHSA-q5cr-j5m6-xrmp

SQL injection vulnerability in index.php in Subdreamer Light, when magic_quotes_gpc is enabled,...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.23%

Top 34% most likely to be exploited

Threat Score 30.4 / 100

Data Sources

NVD EPSS GitHub