Back
CVE-2005-4240
SQL injection vulnerability in search.php in VCD-db 0.98 and earlier allows remote attackers to execute arbitrary SQL commands via the by parameter.
Published: Dec 14, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (6)
| Vendor | Product | Version |
|---|---|---|
| vcd-db | vcd-db | 0.97 |
| vcd-db | vcd-db | 0.98 |
| vcd-db | vcd-db | 0.961 |
| vcd-db | vcd-db | 0.971 |
| vcd-db | vcd-db | 0.972 |
| vcd-db | vcd-db | 0.973 |
GitHub Security Advisory GHSA-5hqm-r2hv-cmwq
SQL injection vulnerability in search.php in VCD-db 0.98 and earlier allows remote attackers to...
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
1.15%
Top 36% most likely to be exploited
Threat Score
30.3 / 100
Data Sources
NVD
EPSS
GitHub