7.5

CVE-2006-2255

Exploit
Multiple SQL injection vulnerabilities in Creative Community Portal 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to (a) ArticleView.php, (2) forum_id parameter to (b) DiscView.php or (c) Discussions.php, (3) event_id parameter to (d) EventView.php, (4) AddVote and (5) answer_id parameter to (e) PollResults.php, or (7) mid parameter to (f) DiscReply.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.38% 0.817
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://pridels0.blogspot.com/2006/05/creative-community-portal-vuln.html
http://secunia.com/advisories/19999
Vendor Advisory
Exploit
http://www.osvdb.org/25307
http://www.osvdb.org/25308
http://www.osvdb.org/25309
http://www.osvdb.org/25310
http://www.osvdb.org/25311
http://www.osvdb.org/25312
http://www.securityfocus.com/bid/17890
http://www.vupen.com/english/advisories/2006/1688
https://exchange.xforce.ibmcloud.com/vulnerabilities/26313