Back

CVE-2005-3845

SQL injection vulnerability in invoices.php in EZ Invoice Inc 2.0 allows remote attackers to execute arbitrary SQL commands via the i parameter. NOTE: the vendor has stated "EZ Invoice, Inc has a patah available. Please email support@ezinvoiceinc.com and EZI will email you the patch to fix this small issue."

Published: Nov 26, 2005 Modified: Jun 16, 2026
CWE-89

CVSS Metrics

Affected Products (1)

Vendor Product Version
ezinvoiceinc ez_invoice_inc 2.0

GitHub Security Advisory GHSA-c7fq-r67j-w9rc

SQL injection vulnerability in invoices.php in EZ Invoice Inc 2.0 allows remote attackers to...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.10%

Top 37% most likely to be exploited

Threat Score 30.3 / 100

Data Sources

NVD EPSS GitHub