CVE-2005-1633

JGS-Portal < 3.0.2 - SQL Injection via Multiple Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 7 public exploits for CVE-2005-1633. PoCs published by [email protected].

AI-analyzed exploit summary The provided text describes SQL injection and XSS vulnerabilities in JGS-Portal, with an example URL demonstrating the SQL injection vector. It lacks executable exploit code but provides technical details about the vulnerabilities.

Description

Multiple SQL injection vulnerabilities in JGS-XA JGS-Portal 3.0.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) anzahl_beitraege parameter to jgs_portal.php, 2) year parameter to (jgs_portal_statistik.php, 3) year parameter to (jgs_portal_beitraggraf.php, 4) tag parameter to (jgs_portal_viewsgraf.php, 5) year parameter to (jgs_portal_themengraf.php, 6) year parameter to (jgs_portal_mitgraf.php, 7) id parameter to jgs_portal_sponsor.php, or (8) the Accept-Language header to jgs_portal_log.php.

Exploits (7)

exploitdb WRITEUP VERIFIED
by [email protected] · textwebappsphp
https://www.exploit-db.com/exploits/25676

The provided text describes SQL injection and XSS vulnerabilities in JGS-Portal, with an example URL demonstrating the SQL injection vector. It lacks executable exploit code but provides technical details about the vulnerabilities.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: JGS-Portal
No auth needed
Prerequisites: Access to the vulnerable JGS-Portal instance
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by [email protected] · textwebappsphp
https://www.exploit-db.com/exploits/25677

The provided text describes SQL injection and XSS vulnerabilities in JGS-Portal due to improper input sanitization. It includes a sample URL demonstrating the SQL injection vector but lacks executable exploit code.

Classification
Writeup 90%
Attack Type
Sqli | Xss
Complexity
Trivial
Reliability
Theoretical
Target: JGS-Portal (version unspecified)
No auth needed
Prerequisites: Access to the vulnerable JGS-Portal instance
MITRE ATT&CK
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by [email protected] · textwebappsphp
https://www.exploit-db.com/exploits/25673

The provided text describes SQL injection and XSS vulnerabilities in JGS-Portal, with example URLs demonstrating unsanitized input in the 'month' and 'year' parameters. No actual exploit code is present.

Classification
Writeup 90%
Attack Type
Sqli | Xss
Complexity
Trivial
Reliability
Theoretical
Target: JGS-Portal
No auth needed
Prerequisites: Access to the vulnerable JGS-Portal instance
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by [email protected] · textwebappsphp
https://www.exploit-db.com/exploits/25679

The provided text describes SQL injection and XSS vulnerabilities in JGS-Portal but does not include functional exploit code. It references a generic example URL for SQL injection without implementation details.

Classification
Writeup 90%
Attack Type
Sqli | Xss
Complexity
Trivial
Reliability
Theoretical
Target: JGS-Portal (version unspecified)
No auth needed
Prerequisites: Network access to the target application
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by [email protected] · textwebappsphp
https://www.exploit-db.com/exploits/25678

The provided text describes SQL injection and XSS vulnerabilities in JGS-Portal due to insufficient input sanitization. It includes a sample URL demonstrating the SQL injection vector but lacks executable exploit code.

Classification
Writeup 90%
Attack Type
Sqli | Xss
Complexity
Trivial
Reliability
Theoretical
Target: JGS-Portal (version not specified)
No auth needed
Prerequisites: Access to the vulnerable JGS-Portal instance
MITRE ATT&CK
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by [email protected] · textwebappsphp
https://www.exploit-db.com/exploits/25675

The provided text describes SQL injection and XSS vulnerabilities in JGS-Portal due to improper input sanitization. It includes an example URL demonstrating the SQL injection vector but lacks executable exploit code.

Classification
Writeup 90%
Attack Type
Sqli | Xss
Complexity
Trivial
Reliability
Theoretical
Target: JGS-Portal (version unspecified)
No auth needed
Prerequisites: Access to the vulnerable JGS-Portal instance
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by [email protected] · textwebappsphp
https://www.exploit-db.com/exploits/25674

The provided text describes SQL injection and XSS vulnerabilities in JGS-Portal but does not include actual exploit code. It references a generic example URL for SQL injection without technical details or payloads.

Classification
Writeup 90%
Attack Type
Sqli | Xss
Complexity
Trivial
Reliability
Theoretical
Target: JGS-Portal (version unspecified)
No auth needed
Prerequisites: Access to the vulnerable JGS-Portal instance
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=111627681218415&w=2

Scores

EPSS 0.0200
EPSS Percentile 78.7%

Details

Status published
Products (1)
jgs-xa/jgs-portal < 3.0.2
Published May 17, 2005
Tracked Since Feb 18, 2026