7.5
CVE-2006-3794
- EPSS 1.56%
- Veröffentlicht 24.07.2006 12:19:00
- Zuletzt bearbeitet 16.06.2026 22:27:49
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
SQL injection vulnerability in Amazing Flash AFCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the search field. NOTE: the vendor has disputed this issue, stating "if someone were to type in any sql injection code, that code would never be queried.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.56% | 0.72 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://securityreason.com/securityalert/1255
http://securitytracker.com/id?1016538
http://www.osvdb.org/28618
http://www.securityfocus.com/archive/1/440589/100/0/threaded
http://www.securityfocus.com/archive/1/440848/100/100/threaded
http://www.securityfocus.com/bid/19074
https://exchange.xforce.ibmcloud.com/vulnerabilities/27846