10

CVE-2006-1000

Exploit
Multiple SQL injection vulnerabilities in Pentacle In-Out Board 3.0 and earlier allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) newsid parameter to newsdetailsview.asp and (2) password parameter to login.asp.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
G2softPentacle In-out Board Version6.03
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.31% 0.87
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/042524.html
http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/042525.html
http://secunia.com/advisories/19024
Vendor Advisory
Exploit
http://securitytracker.com/id?1015682
Vendor Advisory
Exploit
http://www.nukedx.com/?viewdoc=13
Vendor Advisory
Exploit
http://www.nukedx.com/?viewdoc=14
Vendor Advisory
Exploit
http://www.securityfocus.com/archive/1/426074/100/0/threaded
http://www.securityfocus.com/archive/1/426075/100/0/threaded
http://www.securityfocus.com/bid/16818
Vendor Advisory
Exploit
http://www.vupen.com/english/advisories/2006/0749