7.5
CVE-2006-5962
- EPSS 1.31%
- Veröffentlicht 17.11.2006 01:07:00
- Zuletzt bearbeitet 16.06.2026 22:32:13
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple SQL injection vulnerabilities in Hpecs Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields in the (a) login screen, and (3) searchstring parameter in (b) insearch_list.asp.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.31% | 0.67 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
https://www.exploit-db.com/exploits/2782
http://secunia.com/advisories/22904
http://securityreason.com/securityalert/1879
http://www.securityfocus.com/archive/1/451595/100/0/threaded
http://www.vupen.com/english/advisories/2006/4535
https://exchange.xforce.ibmcloud.com/vulnerabilities/30287
https://exchange.xforce.ibmcloud.com/vulnerabilities/30288