Unrated severityNVD Advisory· Published Jun 2, 2005· Updated Apr 16, 2026
CVE-2005-1875
CVE-2005-1875
Description
Multiple SQL injection vulnerabilities in list.php in Exhibit Engine (EE) 1.22 allow remote attackers to execute arbitrary SQL commands via the (1) search_row, (2) sort_row, (3) order or (4) perpage parameter.
Affected products
2cpe:2.3:a:exhibit_engine:exhibit_engine:1.22:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:exhibit_engine:exhibit_engine:1.22:*:*:*:*:*:*:*
- cpe:2.3:a:exhibit_engine:exhibit_engine:1.54_rc4:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- secunia.com/advisories/15583nvdPatchVendor Advisory
- photography-on-the.net/forum/showthread.phpnvdVendor Advisory
- www.osvdb.org/17006nvdVendor Advisory
- www.securityfocus.com/bid/13844nvdVendor Advisory
- marc.infonvd
News mentions
0No linked articles in our index yet.