Back

CVE-2005-4406

SQL injection vulnerability in index.cfm in Mercury CMS 4.0 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter.

Published: Dec 20, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
tmc_visionpool mercury_cms *

GitHub Security Advisory GHSA-pc87-fj52-xq29

SQL injection vulnerability in index.cfm in Mercury CMS 4.0 and earlier allows remote attackers...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.20%

Top 34% most likely to be exploited

Threat Score 30.4 / 100

Data Sources

NVD EPSS GitHub