Back

CVE-2005-1454

SQL injection vulnerability in the radius_xlat function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via (1) group_membership_query, (2) simul_count_query, or (3) simul_verify_query configuration entries.

Published: May 19, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
freeradius freeradius 1.0.2

GitHub Security Advisory GHSA-vpgg-jj2h-wmwf

SQL injection vulnerability in the radius_xlat function in the SQL module for FreeRADIUS 1.0.2...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.79%

Top 23% most likely to be exploited

Threat Score 30.5 / 100

Data Sources

NVD EPSS GitHub