5.1

CVE-2006-1234

SQL injection vulnerability in index.php in DSCounter 1.2, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For field (HTTP_X_FORWARDED_FOR environment variable) in an HTTP header.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DsportalDscounter Version1.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.48% 0.876
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://evuln.com/vulns/98/summary.html
Vendor Advisory
http://secunia.com/advisories/19206
Vendor Advisory
http://securityreason.com/securityalert/627
http://securitytracker.com/id?1015756
http://www.osvdb.org/23882
http://www.securityfocus.com/archive/1/428807/100/0/threaded
http://www.securityfocus.com/bid/17112
http://www.vupen.com/english/advisories/2006/0933
https://exchange.xforce.ibmcloud.com/vulnerabilities/25190