7.5

CVE-2006-1109

Exploit
SQL injection vulnerability in index.asp in Total Ecommerce 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.  NOTE: it is not clear whether this report is associated with a specific product.  If not, then it should not be included in CVE.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.29% 0.665
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/19103
Vendor Advisory
http://securityreason.com/securityalert/530
http://www.nukedx.com/?viewdoc=18
Vendor Advisory
Exploit
http://www.securityfocus.com/archive/1/426765/100/0/threaded
http://www.securityfocus.com/bid/16960
http://www.vupen.com/english/advisories/2006/0840
https://exchange.xforce.ibmcloud.com/vulnerabilities/25045