7.5
CVE-2006-0324
- EPSS 2.51%
- Veröffentlicht 19.01.2006 21:03:00
- Zuletzt bearbeitet 16.06.2026 22:20:20
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
SQL injection vulnerability in WebspotBlogging 3.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter to login.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Webspot ≫ Webspotblogging Version3.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.51% | 0.827 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://evuln.com/vulns/41/summary.html
http://secunia.com/advisories/18560
http://securityreason.com/securityalert/356
http://securitytracker.com/id?1015522
http://www.osvdb.org/22670
http://www.securityfocus.com/archive/1/422364/100/0/threaded
http://www.securityfocus.com/bid/16319
http://www.vupen.com/english/advisories/2006/0268
https://exchange.xforce.ibmcloud.com/vulnerabilities/24222
https://sourceforge.net/forum/forum.php?forum_id=532233
https://sourceforge.net/project/shownotes.php?release_id=387180&group_id=156586