7.5

CVE-2006-0358

Exploit
Multiple SQL injection vulnerabilities in PowerPortal, possibly 1.1 beta through 1.3, allow remote attackers to execute arbitrary SQL commands via the search parameter in (1) index.php and (2) search.php. NOTE: This issue might overlap CVE-2004-0663.2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Powerportal ≫ Powerportal Version 1.1b
Powerportal ≫ Powerportal Version 1.3
Powerportal ≫ Powerportal Version 1.3b
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.33% 0.678
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/10172
http://web.archive.org/web/20050303003128/http://powerportal.sourceforge.net/
http://www.osvdb.org/27957
http://www.osvdb.org/27958
http://www.securityfocus.com/archive/1/422151/100/0/threaded
http://www.securityfocus.com/bid/16279
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/24196