Back

CVE-2005-2625

Incomplete blacklist vulnerability in the checkBlacklist function in CPAINT allows remote attackers to execute arbitrary commands via the (1) ExecuteGlobal function or (2) GetRef statement, which is not included in the blacklist.

Published: Aug 19, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
cpaint cpaint *

GitHub Security Advisory GHSA-7mfh-pq9h-v39p

Incomplete blacklist vulnerability in the checkBlacklist function in CPAINT allows remote...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.80%

Top 23% most likely to be exploited

Threat Score 30.5 / 100

Data Sources

NVD EPSS GitHub