7.5

CVE-2006-3065

SQL injection vulnerability in engine/shards/blog.php in blur6ex 0.3.462 allows remote attackers to execute arbitrary SQL commands via the ID parameter in a proc_reply action in the blog shard.  NOTE: This is a similar vulnerability to CVE-2006-1763, but the affected code and versions are different.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BlursoftBlur6ex Version0.3.462
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.45% 0.7
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/20646
Vendor Advisory
http://securityreason.com/securityalert/1113
http://www.securityfocus.com/archive/1/437015/100/0/threaded
http://www.vupen.com/english/advisories/2006/2341
https://exchange.xforce.ibmcloud.com/vulnerabilities/27120
https://www.exploit-db.com/exploits/1904