CVE-2005-4378 describes a SQL injection vulnerability in Baseline CMS 1.95 and earlier, specifically within the Page.asp component, allowing remote attackers to execute arbitrary SQL commands via the SiteNodeID parameter. This vulnerability carries a CVSS score of 7.5, indicating a high severity with a network-based attack vector, low attack complexity, and potential for partial compromise of confidentiality, integrity, and availability. While no active exploitation is noted and Metasploit/Nuclei exploits are absent, an ExploitDB entry (EDB-26903) exists for multiple input validation vulnerabilities in Baseline CMS 1.95, which may include this flaw. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.95CPE matchmatch criteria | cpe:2.3:a:nma:baseline_cms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.