7.5

CVE-2006-0358

Exploit
Multiple SQL injection vulnerabilities in PowerPortal, possibly 1.1 beta through 1.3, allow remote attackers to execute arbitrary SQL commands via the search parameter in (1) index.php and (2) search.php. NOTE: This issue might overlap CVE-2004-0663.2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PowerportalPowerportal Version1.1b
PowerportalPowerportal Version1.3
PowerportalPowerportal Version1.3b
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.3% 0.667
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/10172
http://web.archive.org/web/20050303003128/http://powerportal.sourceforge.net/
http://www.osvdb.org/27957
http://www.osvdb.org/27958
http://www.securityfocus.com/archive/1/422151/100/0/threaded
http://www.securityfocus.com/bid/16279
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/24196