Back

CVE-2005-4331

SQL injection vulnerability in merchant.ihtml in iHTML Merchant Version 2 Pro allows remote attackers to execute arbitrary SQL commands via the (1) step, (2) id, and (3) pid parameters.

Published: Dec 17, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
ihtml_merchant ihtml_merchant 2_pro

GitHub Security Advisory GHSA-vw4j-qcmc-x4wc

SQL injection vulnerability in merchant.ihtml in iHTML Merchant Version 2 Pro allows remote...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.16%

Top 35% most likely to be exploited

Threat Score 30.3 / 100

Data Sources

NVD EPSS GitHub