Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2005-4227

EPSS 2.56% · P86
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2005-4227

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Multiple "potential" SQL injection vulnerabilities in DCP-Portal 6.1.1 might allow remote attackers to execute arbitrary SQL commands via (1) the password and username parameters in advertiser.php, (2) the aid parameter in announcement.php, (3) the dcp5_member_id, year, agid, day, day_s, hour, minute, month, month_s, and year_s parameters in calendar.php, (4) the cid parameter in contents.php, (5) the dcp5_member_id parameter in forums.php, (6) the bid parameter in go.php, (7) the lid parameter in golink.php, (8) the dcp5_member_id and mid parameters in inbox.php, (9) the catid, dcat, and dl parameters in index.php, (10) the dcp5_member_id in informer.php, (11) the nid parameter in news.php, (12) the type and rate parameters in rate.php, (13) the q parameter in search.php, and (14) the dcp5_member_id in update.php. NOTE: other vectors in the PHP-CHECKER report are also covered by CVE-2005-3365 and CVE-2005-0454.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
DCP-Portal多个跨站脚本和SQL注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
DCP-Portal是一款网站内容管理系统,包括成员管理、投票系统、日历系统等。 DCP-Portal的calendar.php、register.php、index.php等脚本没有充分的验证POST变量,导致跨站脚本和SQL注入攻击,成功利用这些漏洞的攻击者可以远程执行任意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2005-4227

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2005-4227

登录查看更多情报信息。

Same Patch Batch · n/a · 2005-12-14 · 49 CVEs total

CVE-2005-4241VCD-DB跨站脚本攻击漏洞
CVE-2005-4246Plogger Index.PHP SQL注入漏洞
CVE-2005-4250mcGallery PRO目录遍历漏洞
CVE-2005-4242Horde Turba H3 跨站脚本攻击漏洞
CVE-2005-1930Trend Micro ServerProtect RPTServer.ASP 目录遍历漏洞
CVE-2005-3360Trend Micro 多个产品本地不安全许可漏洞
CVE-2005-1929Trend Micro ServerProtect ISANVWRequest 堆溢出漏洞
CVE-2005-1928Trend Micro ServerProtect EarthAgent Daemon拒绝服务漏洞
CVE-2005-3358Linux Kernel set_mempolicy本地拒绝服务漏洞
CVE-2005-4244Snipe Gallery多个输入验证漏洞
CVE-2005-4245Snipe Gallery跨站脚本攻击漏洞
CVE-2005-4240VCD-DB SQL注入漏洞
CVE-2005-4239PHP JackKnife跨站脚本攻击漏洞
CVE-2005-4238Mantis View_filters_page.PHP 跨站脚本攻击漏洞
CVE-2005-4237MySQL Auction 跨站脚本攻击漏洞
CVE-2005-4236CKGold Search.PHP 跨站脚本攻击漏洞
CVE-2005-4235WHMCompleteSolution Knowledgebase.PHP跨站脚本攻击漏洞
CVE-2005-4234EncapsGallery Gallery.PHP SQL注入漏洞
CVE-2005-4233PHP Web Scripts Ad Manager Pro Advertiser_statistic.PHP SQL注入漏洞
CVE-2005-4232Jamit Job Board Index.PHP SQL 注入漏洞

Showing top 20 of 49 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2005-4227

No comments yet


Leave a comment