CVE-2005-4745
published 2005-12-31CVE-2005-4745: SQL injection vulnerability in the rlm_sqlcounter module in FreeRADIUS 1.0.3 and 1.0.4 allows remote attackers to execute arbitrary SQL commands via unknown…
PriorityP335high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.23%
65.7th percentile
SQL injection vulnerability in the rlm_sqlcounter module in FreeRADIUS 1.0.3 and 1.0.4 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | freeradius | < freeradius 1.0.5-1 (bookworm) | freeradius 1.0.5-1 (bookworm) |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | >= 0 < 1.0.5-1 | 1.0.5-1 |
| freeradius | freeradius | >= 0 < 1.0.5-1 | 1.0.5-1 |
| freeradius | freeradius | >= 0 < 1.0.5-1 | 1.0.5-1 |
| freeradius | freeradius | >= 0 < 1.0.5-1 | 1.0.5-1 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fvqf-8h9v-94f2: SQL injection vulnerability in the rlm_sqlcounter module in FreeRADIUS 1
ghsa_unreviewed·2022-05-01
CVE-2005-4745 [HIGH] GHSA-fvqf-8h9v-94f2: SQL injection vulnerability in the rlm_sqlcounter module in FreeRADIUS 1
SQL injection vulnerability in the rlm_sqlcounter module in FreeRADIUS 1.0.3 and 1.0.4 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.
OSV
CVE-2005-4745: SQL injection vulnerability in the rlm_sqlcounter module in FreeRADIUS 1
osv·2005-12-31·CVSS 7.5
CVE-2005-4745 [HIGH] CVE-2005-4745: SQL injection vulnerability in the rlm_sqlcounter module in FreeRADIUS 1
SQL injection vulnerability in the rlm_sqlcounter module in FreeRADIUS 1.0.3 and 1.0.4 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.
Debian
CVE-2005-4745: freeradius - SQL injection vulnerability in the rlm_sqlcounter module in FreeRADIUS 1.0.3 and...
vendor_debian·2005·CVSS 7.5
CVE-2005-4745 [HIGH] CVE-2005-4745: freeradius - SQL injection vulnerability in the rlm_sqlcounter module in FreeRADIUS 1.0.3 and...
SQL injection vulnerability in the rlm_sqlcounter module in FreeRADIUS 1.0.3 and 1.0.4 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.
Scope: local
bookworm: resolved (fixed in 1.0.5-1)
bullseye: resolved (fixed in 1.0.5-1)
forky: resolved (fixed in 1.0.5-1)
sid: resolved (fixed in 1.0.5-1)
trixie: resolved (fixed in 1.0.5-1)
Red Hat
CVE-2005-4745: SQL injection vulnerability in the rlm_sqlcounter module in FreeRADIUS 1
vendor_redhat·CVSS 7.5
CVE-2005-4745 [HIGH] CVE-2005-4745: SQL injection vulnerability in the rlm_sqlcounter module in FreeRADIUS 1
SQL injection vulnerability in the rlm_sqlcounter module in FreeRADIUS 1.0.3 and 1.0.4 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.
Statement: Not vulnerable. This issue did not affect the FreeRADIUS packages as distributed with Red Hat Enterprise Linux 2.1, 3, or 4.
No detection rules found.
No public exploits indexed.
http://www.debian.org/security/2006/dsa-1145http://www.freeradius.org/security.htmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:092http://www.osvdb.org/19323http://www.securityfocus.com/bid/17294http://www.debian.org/security/2006/dsa-1145http://www.freeradius.org/security.htmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:092http://www.osvdb.org/19323http://www.securityfocus.com/bid/17294
2005-12-31
Published