5.1
CVE-2006-2915
- EPSS 1.56%
- Veröffentlicht 23.06.2006 20:06:00
- Zuletzt bearbeitet 16.06.2026 22:26:01
- Quelle PSIRT-CNA@flexerasoftware.com
- CVE-Watchlists
- Unerledigt
Multiple SQL injection vulnerabilities in DeluxeBB 1.06 allow remote attackers to execute arbitrary SQL commands via the (1) hideemail, (2) languagex, (3) xthetimeoffset, and (4) xthetimeformat parameters during account registration.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.56% | 0.72 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.1 | 4.9 | 6.4 |
AV:N/AC:H/Au:N/C:P/I:P/A:P
|
http://secunia.com/advisories/20152
http://secunia.com/secunia_research/2006-44/advisory
http://securityreason.com/securityalert/1134
http://securitytracker.com/id?1016309
http://www.securityfocus.com/archive/1/437228/100/100/threaded
http://www.securityfocus.com/archive/1/438597/100/0/threaded
http://www.vupen.com/english/advisories/2006/2347
http://www.osvdb.org/26457
http://www.securityfocus.com/bid/18453
https://exchange.xforce.ibmcloud.com/vulnerabilities/27091