6.4
CVE-2006-2251
- EPSS 1.37%
- Veröffentlicht 09.05.2006 10:02:00
- Zuletzt bearbeitet 16.06.2026 22:24:38
- Erkennungen
SQL injection vulnerability in the do_mmod function in mod.php in Invision Community Blog (ICB) 1.1.2 final through 1.2 allows remote attackers with moderator privileges to execute arbitrary SQL commands via the selectedbids parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Invision Power Services ≫ Invision Community Blog Version 1.0
Invision Power Services ≫ Invision Community Blog Version 1.1
Invision Power Services ≫ Invision Community Blog Version 1.1.2_final
Invision Power Services ≫ Invision Community Blog Version 1.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.37% | 0.682 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.4 | 10 | 4.9 |
AV:N/AC:L/Au:N/C:P/I:P/A:N
|
http://archives.neohapsis.com/archives/bugtraq/2006-05/0142.html
http://forums.invisionpower.com/index.php?showtopic=214248&view=getnewpost
http://secunia.com/advisories/19973
http://www.osvdb.org/25252
http://www.securityfocus.com/archive/1/433076
http://www.securityfocus.com/bid/17851
https://exchange.xforce.ibmcloud.com/vulnerabilities/26290