7.5

CVE-2006-1778

Multiple SQL injection vulnerabilities in Jeremy Ashcraft Simplog 0.9.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) blogid parameter in (a) index.php and (b) archive.php, the (2) m and (3) y parameters in archive.php, and the (4) sql parameter in (c) server.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SimplogSimplog Version <= 0.9.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.29% 0.898
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://retrogod.altervista.org/simplog_092_incl_xpl.html
http://secunia.com/advisories/19628
Vendor Advisory
http://www.securityfocus.com/archive/1/430743/100/0/threaded
http://www.vupen.com/english/advisories/2006/1332
https://www.exploit-db.com/exploits/1663
http://securitytracker.com/id?1015904
http://securityreason.com/securityalert/702
http://www.osvdb.org/24560
http://www.osvdb.org/24561
http://www.securityfocus.com/bid/17491
https://exchange.xforce.ibmcloud.com/vulnerabilities/25776