7.5
CVE-2006-2300
- EPSS 1.74%
- Veröffentlicht 11.05.2006 10:02:00
- Zuletzt bearbeitet 16.06.2026 22:24:44
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple SQL injection vulnerabilities in EImagePro allow remote attackers to execute arbitrary SQL commands via the (1) CatID parameter to subList.asp, (2) SubjectID parameter to imageList.asp, or (3) Pic parameter to view.asp.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.74% | 0.748 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://downloads.securityfocus.com/vulnerabilities/exploits/eimagepro-xss.txt
http://secunia.com/advisories/20043
http://www.osvdb.org/25331
http://www.osvdb.org/25332
http://www.osvdb.org/25333
http://www.securityfocus.com/bid/17911
http://www.vupen.com/english/advisories/2006/1749
https://exchange.xforce.ibmcloud.com/vulnerabilities/26343