Back

CVE-2005-4010

SQL injection vulnerability in KBase Express 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id parameter to category.php and (2) search parameters to search.php.

Published: Dec 5, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
sensation_designs kbase_express *

GitHub Security Advisory GHSA-4x9r-5p7j-xjmh

SQL injection vulnerability in KBase Express 1.0.0 and earlier allows remote attackers to execute...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.38%

Top 30% most likely to be exploited

Threat Score 30.4 / 100

Data Sources

NVD EPSS GitHub