Unrated severityNVD Advisory· Published Dec 20, 2005· Updated Apr 16, 2026
CVE-2005-4380
CVE-2005-4380
Description
Multiple SQL injection vulnerabilities in Bitweaver 1.1 and 1.1.1 beta allow remote attackers to execute arbitrary SQL commands via the (1) sort_mode parameter to (a) fisheye/list_galleries.php, (b) messages/message_box.php, and (c) users/my.php; the (2) post_id parameter to (d) blogs/view_post.php; and the (3) blog_id parameter to (e) blogs/view.php, which are not properly cleansed by the convert_sortmode function in kernel/BitDb.php.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- www.vupen.com/english/advisories/2005/2975nvdVendor Advisory
- pridels0.blogspot.com/2005/12/bitweaver-multiple-vuln.htmlnvd
- www.bitweaver.org/forums/viewtopic.phpnvd
- www.osvdb.org/21919nvd
- www.osvdb.org/21920nvd
- www.osvdb.org/21921nvd
- www.osvdb.org/21922nvd
- www.osvdb.org/21923nvd
- www.securityfocus.com/bid/15962nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/23814nvd
News mentions
0No linked articles in our index yet.