7.5
CVE-2006-0358
- EPSS 1.33%
- Veröffentlicht 22.01.2006 20:03:00
- Zuletzt bearbeitet 16.06.2026 22:20:25
- Erkennungen
Multiple SQL injection vulnerabilities in PowerPortal, possibly 1.1 beta through 1.3, allow remote attackers to execute arbitrary SQL commands via the search parameter in (1) index.php and (2) search.php. NOTE: This issue might overlap CVE-2004-0663.2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Powerportal ≫ Powerportal Version 1.1b
Powerportal ≫ Powerportal Version 1.3
Powerportal ≫ Powerportal Version 1.3b
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.33% | 0.678 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://secunia.com/advisories/10172
http://web.archive.org/web/20050303003128/http://powerportal.sourceforge.net/
http://www.osvdb.org/27957
http://www.osvdb.org/27958
http://www.securityfocus.com/archive/1/422151/100/0/threaded
http://www.securityfocus.com/bid/16279
https://exchange.xforce.ibmcloud.com/vulnerabilities/24196