SQL injection vulnerability in invoices.php in EZ Invoice Inc 2.0 allows remote attackers to execute arbitrary SQL commands via the i parameter. NOTE: the vendor has stated "EZ Invoice, Inc has a patah available. Please email support@ezinvoiceinc.com and EZI will email you the patch to fix this small issue."
CVE-2005-3845
NONECVSS 0.0Weaponized
0.0
EchelonGraph verdictMonitorLow exploitation likelihood right now — keep watching.
- No confirmed exploitation signals yet
CISA-KEV: Not listedEPSS: 1%CVSS: —Exploit: NoneExposed: 0
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- —
- EG Score
- 0.0(none)
- EG Risk
- 0
- EPSS
- 62.1%
- KEV
- Not listed
Published
November 26, 2005
Last Modified
April 16, 2026
References (10)
- cve@mitrehttp://pridels0.blogspot.com/2005/11/ez-invoice-inc-v-20-sql-inj.html
- cve@mitrehttp://www.osvdb.org/21369
- cve@mitrehttp://www.securityfocus.com/bid/16133
- cve@mitrehttp://www.vupen.com/english/advisories/2005/2596
- cve@mitrehttps://exchange.xforce.ibmcloud.com/vulnerabilities/23213
- af854a3a-2127-422b-91ae-364da2661108http://pridels0.blogspot.com/2005/11/ez-invoice-inc-v-20-sql-inj.html
- af854a3a-2127-422b-91ae-364da2661108http://www.osvdb.org/21369
- af854a3a-2127-422b-91ae-364da2661108http://www.securityfocus.com/bid/16133
- af854a3a-2127-422b-91ae-364da2661108http://www.vupen.com/english/advisories/2005/2596
- af854a3a-2127-422b-91ae-364da2661108https://exchange.xforce.ibmcloud.com/vulnerabilities/23213
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Publicly available exploits
(1 reference)Working exploit code is in the public domain (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- Exploit-DBEDB-27029✓ verifiedFirst seen Dec 25, 2005
EZ Invoice Inc. EZI 2.0 - 'Invoices.php' SQL Injection
Open source ↗
Frequently asked(4)
What is CVE-2005-3845?
CVE-2005-3845 is a none vulnerability published on November 26, 2005. SQL injection vulnerability in invoices.php in EZ Invoice Inc 2.0 allows remote attackers to execute arbitrary SQL commands via the i parameter. NOTE: the vendor has stated "EZ Invoice, Inc has a patah available. Please email support@ezinvoiceinc.com and EZI will email you the patch to fix this…
When was CVE-2005-3845 disclosed?
CVE-2005-3845 was first published in the National Vulnerability Database on November 26, 2005, with the most recent update on April 16, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2005-3845 actively exploited?
CVE-2005-3845 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 62.1% percentile likelihood of exploitation in the next 30 days — higher percentiles indicate greater predicted risk.
How do I remediate CVE-2005-3845?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2005-3845, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2005-3845
Is Your Infrastructure Affected by CVE-2005-3845?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.