7.5

CVE-2006-4347

SQL injection vulnerability in user logon authentication request handling in Cool_CoolD.exe in Cool Manager 5.0 (5,60,90,28) and Cool Messenger Office/School Server 5.5 (5,65,12,13) allows remote attackers to execute arbitrary SQL commands via the username field.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.43% 0.696
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://archives.neohapsis.com/archives/fulldisclosure/2006-08/0605.html
http://secunia.com/advisories/21569
Patch
Vendor Advisory
http://vuln.sg/coolmessenger55-en.html
Patch
Vendor Advisory
http://www.osvdb.org/28117
http://www.securityfocus.com/bid/19669
http://www.vupen.com/english/advisories/2006/3362
https://exchange.xforce.ibmcloud.com/vulnerabilities/28531