7.5
CVE-2006-3799
- EPSS 1.42%
- Veröffentlicht 24.07.2006 12:19:00
- Zuletzt bearbeitet 16.06.2026 22:27:49
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
DeluxeBB 1.07 and earlier allows remote attackers to bypass SQL injection protection mechanisms via the login variable and certain other variables, by using lowercase "union select" or possibly other statements that do not match the uppercase "UNION SELECT."
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.42% | 0.693 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/047989.html
http://secunia.com/advisories/21116
http://securityreason.com/securityalert/1254
http://www.securityfocus.com/archive/1/440435/100/0/threaded
http://www.securityfocus.com/bid/19052
http://www.vupen.com/english/advisories/2006/2879