Back

CVE-2005-4495

SQL injection vulnerability in index.cfm in SpireMedia mx7 allows remote attackers to execute arbitrary SQL commands via the cid parameter. NOTE: the vendor has disputed this issue, stating "This information is incorrect, unproven, and potentially slanderous." However, CVE and OSVDB have both performed additional research that suggests that this might be path disclosure from invalid SQL syntax

Published: Dec 22, 2005 Modified: Jun 16, 2026
CWE-89

CVSS Metrics

Affected Products (1)

Vendor Product Version
spiremedia mx7 *

GitHub Security Advisory GHSA-h3f6-5p9v-rcxm

** DISPUTED ** SQL injection vulnerability in index.cfm in SpireMedia mx7 allows remote...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.21%

Top 34% most likely to be exploited

Threat Score 30.4 / 100

Data Sources

NVD EPSS GitHub