7.5

CVE-2006-4041

SQL injection vulnerability in Pike before 7.6.86, when using a Postgres database server, allows remote attackers to execute arbitrary SQL commands via unspecified attack vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PikePike Version <= 7.6.66
PikePike Version0.4_pl8
PikePike Version0.5
PikePike Version0.6
PikePike Version7.0
PikePike Version7.2
PikePike Version7.4
PikePike Version7.4.327
PikePike Version7.4.328
PikePike Version7.6
PikePike Version7.6.36
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.67% 0.738
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://pike.ida.liu.se/download/notes/7.6.86.xml
Patch
http://secunia.com/advisories/20494
Patch
Vendor Advisory
http://secunia.com/advisories/21362
Patch
Vendor Advisory
http://secunia.com/advisories/22481
http://security.gentoo.org/glsa/glsa-200608-10.xml
Patch
http://www.securityfocus.com/bid/19367
Patch
http://www.ubuntu.com/usn/usn-367-1
http://www.vupen.com/english/advisories/2006/2209
https://exchange.xforce.ibmcloud.com/vulnerabilities/26992