7.5

CVE-2006-0167

Exploit
SQL injection vulnerability in MyPhPim 01.05 allows remote attackers to execute arbitrary SQL commands via the (1) cal_id parameter in calendar.php3 and the (2) password field on the login page.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MyphpimMyphpim Version01.05
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.14% 0.797
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://evuln.com/vulns/22/summary.html
Vendor Advisory
Exploit
http://secunia.com/advisories/18399
Vendor Advisory
http://www.osvdb.org/22324
http://www.osvdb.org/22325
http://www.securityfocus.com/archive/1/421863/100/0/threaded
http://www.securityfocus.com/bid/16210
Exploit
http://www.vupen.com/english/advisories/2006/0147
https://exchange.xforce.ibmcloud.com/vulnerabilities/24066
https://exchange.xforce.ibmcloud.com/vulnerabilities/24075