6.4
CVE-2006-1920
- EPSS 2%
- Veröffentlicht 20.04.2006 18:06:00
- Zuletzt bearbeitet 16.06.2026 22:23:56
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
SQL injection vulnerability in index.php in PMTool 1.2.2 allows remote attackers to execute arbitrary SQL commands via the order parameter in the include files (1) user.inc.php, (2) customer.inc.php, and (3) project.inc.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2% | 0.782 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.4 | 10 | 4.9 |
AV:N/AC:L/Au:N/C:P/I:P/A:N
|
http://secunia.com/advisories/19685
http://www.osvdb.org/24780
http://www.osvdb.org/24781
http://www.osvdb.org/24782
http://www.securityfocus.com/bid/17599
http://www.vupen.com/english/advisories/2006/1416
https://exchange.xforce.ibmcloud.com/vulnerabilities/25877