Back

CVE-2005-4608

SQL injection vulnerability in index.php in BugPort 1.147 allows remote attackers to execute arbitrary SQL commands via the (1) devWherePair[0], (2) orderBy, and (3) where parameters.

Published: Dec 31, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (109)

Vendor Product Version
incogen bugport 1.039
incogen bugport 1.040
incogen bugport 1.041
incogen bugport 1.042
incogen bugport 1.043
incogen bugport 1.044
incogen bugport 1.045
incogen bugport 1.046
incogen bugport 1.047
incogen bugport 1.048
incogen bugport 1.049
incogen bugport 1.050
incogen bugport 1.051
incogen bugport 1.052
incogen bugport 1.053
incogen bugport 1.054
incogen bugport 1.055
incogen bugport 1.056
incogen bugport 1.057
incogen bugport 1.058

…and 89 more

GitHub Security Advisory GHSA-7763-j2c2-xh5f

SQL injection vulnerability in index.php in BugPort 1.147 allows remote attackers to execute...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.37%

Top 30% most likely to be exploited

Threat Score 30.4 / 100

Data Sources

NVD EPSS GitHub