7.5

CVE-2006-1232

Multiple SQL injection vulnerabilities in DSDownload 1.0, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) key and (2) category parameters to (a) search.php and (b) downloads.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DsportalDsdownload Version1.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.9% 0.889
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://evuln.com/vulns/99/summary.html
http://secunia.com/advisories/19202
Vendor Advisory
http://securityreason.com/securityalert/626
http://securitytracker.com/id?1015755
http://www.osvdb.org/23886
http://www.osvdb.org/23887
http://www.securityfocus.com/archive/1/428808/100/0/threaded
http://www.securityfocus.com/bid/17116
http://www.vupen.com/english/advisories/2006/0934
https://exchange.xforce.ibmcloud.com/vulnerabilities/25193