Back
CVE-2005-3942
SQL injection vulnerability in knowledgebase-control.php in Orca Knowledgebase 2.1b and earlier allows remote attackers to execute arbitrary SQL commands via the qid parameter.
Published: Dec 1, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| greywyvern | orca_knowledgebase | * |
GitHub Security Advisory GHSA-58vm-q7q4-jr96
SQL injection vulnerability in knowledgebase-control.php in Orca Knowledgebase 2.1b and earlier...
References (12)
- http://pridels0.blogspot.com/2005/11/orca-knowledgebase-sql-vuln.html
- http://secunia.com/advisories/17805 Vendor Advisory
- http://www.greywyvern.com/orca#know Patch
- http://www.osvdb.org/21198
- http://www.securityfocus.com/bid/15637 Exploit
- http://www.vupen.com/english/advisories/2005/2642
- http://pridels0.blogspot.com/2005/11/orca-knowledgebase-sql-vuln.html
- http://secunia.com/advisories/17805 Vendor Advisory
- http://www.greywyvern.com/orca#know Patch
- http://www.osvdb.org/21198
- http://www.securityfocus.com/bid/15637 Exploit
- http://www.vupen.com/english/advisories/2005/2642
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
1.35%
Top 31% most likely to be exploited
Threat Score
30.4 / 100
Data Sources
NVD
EPSS
GitHub