6.5
CVE-2006-5150
- EPSS 0.99%
- Veröffentlicht 05.10.2006 04:04:00
- Zuletzt bearbeitet 16.06.2026 22:30:35
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
SQL injection vulnerability in the reports system in OpenBiblio before 0.5.2 allows remote attackers with report privileges to execute arbitrary SQL commands via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Openbiblio ≫ Openbiblio Version <= 0.5.1
Openbiblio ≫ Openbiblio Version0.1.0
Openbiblio ≫ Openbiblio Version0.2.1
Openbiblio ≫ Openbiblio Version0.3.0
Openbiblio ≫ Openbiblio Version0.4.0
Openbiblio ≫ Openbiblio Version0.5.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.99% | 0.579 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|
http://secunia.com/advisories/22238
http://sourceforge.net/project/shownotes.php?release_id=451780
http://www.securityfocus.com/bid/20301
http://www.vupen.com/english/advisories/2006/3867
https://exchange.xforce.ibmcloud.com/vulnerabilities/29318