7.5

CVE-2006-5840

Exploit
Multiple SQL injection vulnerabilities in Abarcar Realty Portal allow remote attackers to execute arbitrary SQL commands via the (1) neid parameter to newsdetails.php, or the (2) slid parameter to slistl.php. NOTE: the cat vector is already covered by CVE-2006-2853.  NOTE: the vendor has notified CVE that the current version only creates static pages, and that slistl.php/slid never existed in any version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AbarcarAbarcar Realty Portal Version5.1.5
AbarcarAbarcar Realty Portal Version6.0.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.03% 0.785
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

http://attrition.org/pipermail/vim/2006-December/001190.html
Mailing List
http://s-a-p.ca/index.php?page=OurAdvisories&id=7
URL Repurposed
http://secunia.com/advisories/22792
Vendor Advisory
http://securityreason.com/securityalert/1840
Third Party Advisory
http://www.attrition.org/pipermail/vim/2006-December/001170.html
Mailing List
http://www.osvdb.org/30249
Broken Link
http://www.osvdb.org/30250
Broken Link
http://www.securityfocus.com/archive/1/450946/100/0/threaded
Third Party Advisory
http://www.securityfocus.com/bid/20970
Patch
Exploit
http://www.vupen.com/english/advisories/2006/4418
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/30135
Third Party Advisory