CVE-2005-4495

SpireMedia mx7 - SQL Injection via cid Parameter

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in index.cfm in SpireMedia mx7 allows remote attackers to execute arbitrary SQL commands via the cid parameter. NOTE: the vendor has disputed this issue, stating "This information is incorrect, unproven, and potentially slanderous." However, CVE and OSVDB have both performed additional research that suggests that this might be path disclosure from invalid SQL syntax

References (4)

Core 4
Core References
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2005/3053
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/16039
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/22066

Scores

EPSS 0.0121
EPSS Percentile 65.4%

Details

CWE
CWE-89
Status published
Products (1)
spiremedia/mx7
Published Dec 22, 2005
Tracked Since Feb 18, 2026