Lucene search

K
cveMitreCVE-2006-0200
HistoryJan 13, 2006 - 11:03 p.m.

CVE-2006-0200

2006-01-1323:03:00
CWE-134
mitre
web.nvd.nist.gov
36
cve
php
mysqli
format string vulnerability
code execution
nvd
security

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.118

Percentile

95.3%

Format string vulnerability in the error-reporting feature in the mysqli extension in PHP 5.1.0 and 5.1.1 might allow remote attackers to execute arbitrary code via format string specifiers in MySQL error messages.

Affected configurations

Nvd
Node
phpphpMatch5.1.0
OR
phpphpMatch5.1.1
VendorProductVersionCPE
phpphp5.1.0cpe:2.3:a:php:php:5.1.0:*:*:*:*:*:*:*
phpphp5.1.1cpe:2.3:a:php:php:5.1.1:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.118

Percentile

95.3%