7.5
CVE-2006-3515
- EPSS 1.46%
- Veröffentlicht 11.07.2006 23:05:00
- Zuletzt bearbeitet 16.06.2026 22:27:13
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
SQL injection vulnerability in the loginADP function in ajaxp.php in AjaxPortal 3.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password parameters.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Myiosoft.Com ≫ Ajaxportal Version3.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.46% | 0.702 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://secunia.com/advisories/20985
http://securityreason.com/securityalert/1206
http://www.kapda.ir/advisory-355.html
http://www.osvdb.org/27067
http://www.securityfocus.com/archive/1/439521/100/0/threaded
http://www.securityfocus.com/archive/1/439614/100/0/threaded
http://www.securityfocus.com/bid/18897
http://www.vupen.com/english/advisories/2006/2714