7.5
CVE-2006-6937
- EPSS 1.17%
- Veröffentlicht 17.01.2007 00:28:00
- Zuletzt bearbeitet 16.06.2026 22:34:05
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
SQL injection vulnerability in displaypic.asp in Xtreme ASP Photo Gallery allows remote attackers to inject arbitrary SQL commands via the sortorder parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Pensacola Web Designs ≫ Xtremeasp Photogallery Version2.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.17% | 0.633 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://securityreason.com/securityalert/2148
http://www.securityfocus.com/archive/1/451786/100/0/threaded
http://www.securityfocus.com/bid/21138
http://aria-security.net/advisory/xtremeg.txt
http://www.osvdb.org/31507
https://exchange.xforce.ibmcloud.com/vulnerabilities/30324