Lucene search

K
cveMitreCVE-2006-2244
HistoryMay 09, 2006 - 10:02 a.m.

CVE-2006-2244

2006-05-0910:02:00
mitre
web.nvd.nist.gov
26
cve
sql injection
web4future news portal
security vulnerability
nvd

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

AI Score

8.5

Confidence

Low

EPSS

0.006

Percentile

78.5%

Multiple SQL injection vulnerabilities in Web4Future News Portal allow remote attackers to execute arbitrary SQL commands via the ID parameter to (1) comentarii.php or (2) view.php.

Affected configurations

Nvd
Node
web4futurenews_portal
VendorProductVersionCPE
web4futurenews_portal*cpe:2.3:a:web4future:news_portal:*:*:*:*:*:*:*:*

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

AI Score

8.5

Confidence

Low

EPSS

0.006

Percentile

78.5%

Related for CVE-2006-2244