7.5

CVE-2006-0727

SQL injection vulnerability in mstrack.php in MusOX DF MSAnalysis (DFMSA), as used in some environments that use CPG-Nuke Dragonfly CMS, allows remote attackers to trigger path disclosure from a SQL syntax error, and possibly execute arbitrary SQL commands, via certain query data, probably involving the profile name.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MusoxDf Msanalysis Version1.0.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.15% 0.797
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://dragonflycms.org/Forums/viewtopic/t=14751.html
http://dragonflycms.org/Forums/viewtopic/t=14877/postdays=0/postorder=asc/start=15.html
http://dragonflycms.org/cvs/html/includes/functions/linking.php?b=9.19.2
http://dragonflycms.org/cvs/html/includes/functions/linking.php?d=9.23-9.22
http://www.osvdb.org/23060
http://www.vupen.com/english/advisories/2006/0688
http://www.osvdb.org/23250
http://www.securityfocus.com/bid/16783