CVE-2005-1011

SiteEnable - SQL Injection via content.asp sortby Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2005-1011. PoCs published by Zinho.

AI-analyzed exploit summary The exploit demonstrates an SQL injection vulnerability in SiteEnable by injecting a malicious SQL query via the 'sortby' parameter. The payload disrupts the original query logic, potentially allowing unauthorized data access or manipulation.

Description

SQL injection vulnerability in content.asp in SiteEnable allows remote attackers to execute arbitrary SQL commands via the sortby parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Zinho · textwebappsasp
https://www.exploit-db.com/exploits/25332

The exploit demonstrates an SQL injection vulnerability in SiteEnable by injecting a malicious SQL query via the 'sortby' parameter. The payload disrupts the original query logic, potentially allowing unauthorized data access or manipulation.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: SiteEnable (all versions)
No auth needed
Prerequisites: Access to the vulnerable web application endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/12985
Exploit vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1013631

Scores

EPSS 0.0239
EPSS Percentile 81.8%

Details

Status published
Products (1)
iatek/siteenable
Published May 02, 2005
Tracked Since Feb 18, 2026