7.5
CVE-2006-5145
- EPSS 1.09%
- Veröffentlicht 05.10.2006 04:04:00
- Zuletzt bearbeitet 16.06.2026 22:30:35
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple SQL injection vulnerabilities in OlateDownload 3.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) page parameter in details.php or the (2) query parameter in search.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Olate ≫ Olatedownload Version3.4.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.09% | 0.61 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://secunia.com/advisories/22241
http://securityreason.com/securityalert/1680
http://www.securityfocus.com/archive/1/447424/100/0/threaded
http://www.securityfocus.com/bid/20278
https://exchange.xforce.ibmcloud.com/vulnerabilities/29294