7.8
CVE-2006-1541
- EPSS 2.26%
- Veröffentlicht 30.03.2006 11:02:00
- Zuletzt bearbeitet 16.06.2026 22:23:09
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
SQL injection vulnerability in Default.asp in EzASPSite 2.0 RC3 and earlier allows remote attackers to execute arbitrary SQL commands and obtain the SHA1 hash of the admin password via the Scheme parameter.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.26% | 0.807 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 10 | 6.9 |
AV:N/AC:L/Au:N/C:C/I:N/A:N
|
http://marc.info/?l=full-disclosure&m=114367573519326&w=2
http://secunia.com/advisories/19441
http://www.nukedx.com/?viewdoc=22
http://www.osvdb.org/24256
http://www.securityfocus.com/archive/1/429487/100/0/threaded
http://www.securityfocus.com/bid/17309
http://www.vupen.com/english/advisories/2006/1164
https://exchange.xforce.ibmcloud.com/vulnerabilities/25544
https://www.exploit-db.com/exploits/1623