Lucene search

K
cveMitreCVE-2006-2139
HistoryMay 02, 2006 - 10:02 a.m.

CVE-2006-2139

2006-05-0210:02:00
mitre
web.nvd.nist.gov
26
cve
sql injection
php newsfeed
nvd
vulnerability

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

AI Score

8.6

Confidence

Low

EPSS

0.006

Percentile

78.9%

Multiple SQL injection vulnerabilities in PHP Newsfeed 20040723 allow remote attackers to execute arbitrary SQL commands via the (1) name parameter to (a) deltables.php, (2) select, (3) header, (4) url, (5) source, or (6) time parameters to (b) manualsubmit.php, (7) num parameter to © delete.php, or (8) tablename parameter to (d) searchnews.php.

Affected configurations

Nvd
Node
wilsonncareabusinessesphp_newsfeedMatch2004-07-23
VendorProductVersionCPE
wilsonncareabusinessesphp_newsfeed2004-07-23cpe:2.3:a:wilsonncareabusinesses:php_newsfeed:2004-07-23:*:*:*:*:*:*:*

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

AI Score

8.6

Confidence

Low

EPSS

0.006

Percentile

78.9%

Related for CVE-2006-2139