Lucene search

K
cveMitreCVE-2006-0542
HistoryFeb 04, 2006 - 2:02 a.m.

CVE-2006-0542

2006-02-0402:02:00
mitre
web.nvd.nist.gov
26
cve-2006-0542
sql injection
config.php
nukedweb
guestbookhost
remote attackers
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.6

Confidence

Low

EPSS

0.007

Percentile

80.9%

Multiple SQL injection vulnerabilities in config.php in NukedWeb GuestBookHost 2005.04.25 allow remote attackers to execute arbitrary SQL commands via the (1) email and (2) password parameters.

Affected configurations

Nvd
Node
nukedwebguestbookhostMatch2005-04-25
VendorProductVersionCPE
nukedwebguestbookhost2005-04-25cpe:2.3:a:nukedweb:guestbookhost:2005-04-25:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.6

Confidence

Low

EPSS

0.007

Percentile

80.9%