Back
CVE-2005-4382
SQL injection vulnerability in CitySoft Community Enterprise 4.x allows remote attackers to execute arbitrary SQL commands via the (1) nodeID, (2) pageID, (3) ID, and (4) parentid parameter to index.cfm; and (5) documentFormatId parameter to document/docWindow.cfm.
Published: Dec 20, 2005
Modified: Jun 16, 2026
CWE-89
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| citysoft | community_enterprise | * |
GitHub Security Advisory GHSA-hf2f-mj6g-rh32
SQL injection vulnerability in CitySoft Community Enterprise 4.x allows remote attackers to...
References (12)
- http://pridels0.blogspot.com/2005/12/community-enterprise-4x-multiple-vuln.html
- http://secunia.com/advisories/18145/ Vendor Advisory
- http://www.osvdb.org/21855
- http://www.osvdb.org/21969
- http://www.vupen.com/english/advisories/2005/2979 Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23818
- http://pridels0.blogspot.com/2005/12/community-enterprise-4x-multiple-vuln.html
- http://secunia.com/advisories/18145/ Vendor Advisory
- http://www.osvdb.org/21855
- http://www.osvdb.org/21969
- http://www.vupen.com/english/advisories/2005/2979 Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23818
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
1.33%
Top 31% most likely to be exploited
Threat Score
30.4 / 100
Data Sources
NVD
EPSS
GitHub