CVE-2005-4065: SQL Injection
Published Dec 7, 2005
·Updated
SQL injection vulnerability in the search module in Edgewall Trac before 0.9.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
Affected Software
6 affected components
Edgewall Software Trac=0.7.1
Edgewall Software Trac=0.8.1
Edgewall Software Trac=0.8.3
Edgewall Software Trac=0.8.4
Edgewall Software Trac=0.9
Edgewall Software Trac=0.9.1
Remediation
Patch Available
Patch Available
Event History
Dec 7, 2005
CVE Published
11:03 AM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-4065?
CVE-2005-4065 is considered a critical vulnerability due to its potential to allow remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2005-4065?
To fix CVE-2005-4065, upgrade to Edgewall Trac version 0.9.2 or later, which contains the patch for this vulnerability.
3
What versions of Edgewall Trac are affected by CVE-2005-4065?
CVE-2005-4065 affects Edgewall Trac versions 0.7.1, 0.8.1, 0.8.3, 0.8.4, and 0.9.0 to 0.9.1.
4
Can CVE-2005-4065 be exploited remotely?
Yes, CVE-2005-4065 can be exploited remotely without the need for local access.
5
What type of attack does CVE-2005-4065 facilitate?
CVE-2005-4065 facilitates SQL injection attacks, allowing attackers to manipulate database queries.