5.1

CVE-2006-2915

Multiple SQL injection vulnerabilities in DeluxeBB 1.06 allow remote attackers to execute arbitrary SQL commands via the (1) hideemail, (2) languagex, (3) xthetimeoffset, and (4) xthetimeformat parameters during account registration.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DeluxebbDeluxebb Version1.06
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.56% 0.72
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/20152
Vendor Advisory
http://secunia.com/secunia_research/2006-44/advisory
Vendor Advisory
http://securityreason.com/securityalert/1134
http://securitytracker.com/id?1016309
http://www.securityfocus.com/archive/1/437228/100/100/threaded
http://www.securityfocus.com/archive/1/438597/100/0/threaded
http://www.vupen.com/english/advisories/2006/2347
http://www.osvdb.org/26457
http://www.securityfocus.com/bid/18453
https://exchange.xforce.ibmcloud.com/vulnerabilities/27091