CVE-2005-1454
published 2005-05-19CVE-2005-1454: SQL injection vulnerability in the radius_xlat function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote authenticated users to execute…
PriorityP432high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.79%
76.0th percentile
SQL injection vulnerability in the radius_xlat function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via (1) group_membership_query, (2) simul_count_query, or (3) simul_verify_query configuration entries.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | freeradius | < freeradius 1.0.2-4 (bookworm) | freeradius 1.0.2-4 (bookworm) |
| freeradius | freeradius | — | — |
| freeradius | freeradius | >= 0 < 1.0.2-4 | 1.0.2-4 |
| freeradius | freeradius | >= 0 < 1.0.2-4 | 1.0.2-4 |
| freeradius | freeradius | >= 0 < 1.0.2-4 | 1.0.2-4 |
| freeradius | freeradius | >= 0 < 1.0.2-4 | 1.0.2-4 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2005-05-04·CVSS 7.5
CVE-2005-1454 [HIGH] security flaw
security flaw
SQL injection vulnerability in the radius_xlat function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via (1) group_membership_query, (2) simul_count_query, or (3) simul_verify_query configuration entries.
Debian
CVE-2005-1454: freeradius - SQL injection vulnerability in the radius_xlat function in the SQL module for Fr...
vendor_debian·2005·CVSS 7.5
CVE-2005-1454 [HIGH] CVE-2005-1454: freeradius - SQL injection vulnerability in the radius_xlat function in the SQL module for Fr...
SQL injection vulnerability in the radius_xlat function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via (1) group_membership_query, (2) simul_count_query, or (3) simul_verify_query configuration entries.
Scope: local
bookworm: resolved (fixed in 1.0.2-4)
bullseye: resolved (fixed in 1.0.2-4)
forky: resolved (fixed in 1.0.2-4)
sid: resolved (fixed in 1.0.2-4)
trixie: resolved (fixed in 1.0.2-4)
GHSA
GHSA-vpgg-jj2h-wmwf: SQL injection vulnerability in the radius_xlat function in the SQL module for FreeRADIUS 1
ghsa_unreviewed·2022-05-01
CVE-2005-1454 [HIGH] GHSA-vpgg-jj2h-wmwf: SQL injection vulnerability in the radius_xlat function in the SQL module for FreeRADIUS 1
SQL injection vulnerability in the radius_xlat function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via (1) group_membership_query, (2) simul_count_query, or (3) simul_verify_query configuration entries.
OSV
CVE-2005-1454: SQL injection vulnerability in the radius_xlat function in the SQL module for FreeRADIUS 1
osv·2005-05-19·CVSS 7.5
CVE-2005-1454 [HIGH] CVE-2005-1454: SQL injection vulnerability in the radius_xlat function in the SQL module for FreeRADIUS 1
SQL injection vulnerability in the radius_xlat function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via (1) group_membership_query, (2) simul_count_query, or (3) simul_verify_query configuration entries.
No detection rules found.
No public exploits indexed.
http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2005-05/0492.htmlhttp://www.freeradius.org/security.htmlhttp://www.gentoo.org/security/en/glsa/glsa-200505-13.xmlhttp://www.novell.com/linux/security/advisories/2005_14_sr.htmlhttp://www.redhat.com/support/errata/RHSA-2005-524.htmlhttp://www.securityfocus.com/bid/13540http://www.securitytracker.com/alerts/2005/May/1013909.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/20449https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9610http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2005-05/0492.htmlhttp://www.freeradius.org/security.htmlhttp://www.gentoo.org/security/en/glsa/glsa-200505-13.xmlhttp://www.novell.com/linux/security/advisories/2005_14_sr.htmlhttp://www.redhat.com/support/errata/RHSA-2005-524.htmlhttp://www.securityfocus.com/bid/13540http://www.securitytracker.com/alerts/2005/May/1013909.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/20449https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9610
2005-05-19
Published