Lucene search

K
cve[email protected]CVE-2006-1238
HistoryMar 15, 2006 - 4:06 p.m.

CVE-2006-1238

2006-03-1516:06:00
web.nvd.nist.gov
26
sql injection
dslogin 1.0
remote attackers
authentication bypass

5.1 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

8.6 High

AI Score

Confidence

Low

0.014 Low

EPSS

Percentile

86.6%

SQL injection vulnerability in DSLogin 1.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the $log_userid variable in (1) index.php and (2) admin/index.php.

Affected configurations

NVD
Node
dsportaldsloginMatch1.0
CPENameOperatorVersion
dsportal:dslogindsportal dslogineq1.0

5.1 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

8.6 High

AI Score

Confidence

Low

0.014 Low

EPSS

Percentile

86.6%

Related for CVE-2006-1238