Back

CVE-2005-4240

SQL injection vulnerability in search.php in VCD-db 0.98 and earlier allows remote attackers to execute arbitrary SQL commands via the by parameter.

Published: Dec 14, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (6)

Vendor Product Version
vcd-db vcd-db 0.97
vcd-db vcd-db 0.98
vcd-db vcd-db 0.961
vcd-db vcd-db 0.971
vcd-db vcd-db 0.972
vcd-db vcd-db 0.973

GitHub Security Advisory GHSA-5hqm-r2hv-cmwq

SQL injection vulnerability in search.php in VCD-db 0.98 and earlier allows remote attackers to...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.15%

Top 36% most likely to be exploited

Threat Score 30.3 / 100

Data Sources

NVD EPSS GitHub