Back
CVE-2005-4495
SQL injection vulnerability in index.cfm in SpireMedia mx7 allows remote attackers to execute arbitrary SQL commands via the cid parameter. NOTE: the vendor has disputed this issue, stating "This information is incorrect, unproven, and potentially slanderous." However, CVE and OSVDB have both performed additional research that suggests that this might be path disclosure from invalid SQL syntax
Published: Dec 22, 2005
Modified: Jun 16, 2026
CWE-89
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| spiremedia | mx7 | * |
GitHub Security Advisory GHSA-h3f6-5p9v-rcxm
** DISPUTED ** SQL injection vulnerability in index.cfm in SpireMedia mx7 allows remote...
References (8)
- http://pridels0.blogspot.com/2005/12/spiremedia-cms-sql-inj-vuln.html
- http://www.osvdb.org/22066
- http://www.securityfocus.com/bid/16039
- http://www.vupen.com/english/advisories/2005/3053 Vendor Advisory
- http://pridels0.blogspot.com/2005/12/spiremedia-cms-sql-inj-vuln.html
- http://www.osvdb.org/22066
- http://www.securityfocus.com/bid/16039
- http://www.vupen.com/english/advisories/2005/3053 Vendor Advisory
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
1.21%
Top 34% most likely to be exploited
Threat Score
30.4 / 100
Data Sources
NVD
EPSS
GitHub