Lucene search

K
cve[email protected]CVE-2006-0345
HistoryJan 21, 2006 - 1:03 a.m.

CVE-2006-0345

2006-01-2101:03:00
web.nvd.nist.gov
22
saralblog
sql injection
vulnerability
remote attackers
search parameter

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.4 High

AI Score

Confidence

Low

0.008 Low

EPSS

Percentile

81.7%

Multiple SQL injection vulnerabilities in SaralBlog 1.0 allow remote attackers to execute arbitrary SQL commands via the search parameter to search.php. NOTE: the id/viewprofile.php issue is already covered by CVE-2005-4058.

Affected configurations

NVD
Node
saral_kaushiksaralblogMatch1.0

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.4 High

AI Score

Confidence

Low

0.008 Low

EPSS

Percentile

81.7%

Related for CVE-2006-0345