7.5

CVE-2006-1560

Multiple SQL injection vulnerabilities in SkinTech phpNewsManager 1.48 allow remote attackers to execute arbitrary SQL commands via unspecified parameters, possibly (1) id and (2) topicid, in (a) browse.php, (b) category.php, (c) gallery.php, (d) poll.php, and (e) possibly other unspecified scripts.  NOTE: portions of the description details are obtained from third party information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SkintechPhpnewsmanager Version1.48
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.85% 0.764
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://evuln.com/vulns/110
http://secunia.com/advisories/19391
http://securityreason.com/securityalert/680
http://www.osvdb.org/24265
http://www.osvdb.org/24266
http://www.osvdb.org/24267
http://www.osvdb.org/24268
http://www.securityfocus.com/archive/1/430311/100/0/threaded
http://www.securityfocus.com/archive/1/430478/100/0/threaded
http://www.securityfocus.com/bid/17301
http://www.vupen.com/english/advisories/2006/1152
https://exchange.xforce.ibmcloud.com/vulnerabilities/25512