7.5

CVE-2006-3348

Multiple SQL injection vulnerabilities in HSPcomplete 3.2.2 and 3.3 Beta and earlier allow remote attackers to execute arbitrary SQL commands via the (1) type parameter in report.php and (2) level parameter in custom_buttons.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Swsoft ≫ Hspcomplete Version <= 3.3_beta
Swsoft ≫ Hspcomplete Version 3.2.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.11% 0.628
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://pridels0.blogspot.com/2006/06/hspcomplete-vuln.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/27379