6.5

CVE-2006-3996

Exploit
SQL injection vulnerability in links/index.php in ATutor 1.5.3.1 and earlier allows remote authenticated users to execute arbitrary SQL commands via the (1) desc or (2) asc parameters.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.67% 0.737
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://atutor.ca/news.php#010806
http://retrogod.altervista.org/atutor_1531_sql.html
Exploit
http://secunia.com/advisories/21308
Patch
Vendor Advisory
http://securityreason.com/securityalert/1330
http://www.osvdb.org/27665
http://www.securityfocus.com/archive/1/441711/100/0/threaded
http://www.securityfocus.com/bid/19232
http://www.vupen.com/english/advisories/2006/3074
https://exchange.xforce.ibmcloud.com/vulnerabilities/28082
https://www.exploit-db.com/exploits/2088