Lucene search

K
cve[email protected]CVE-2006-3249
HistoryJun 27, 2006 - 10:05 a.m.

CVE-2006-3249

2006-06-2710:05:00
web.nvd.nist.gov
28
cve
2006
3249
sql injection
vulnerability
phorum
remote attackers
arbitrary
commands
page parameter
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.5 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

79.5%

SQL injection vulnerability in search.php in Phorum 5.1.14 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the vendor has disputed this report, stating “If a non positive integer or non-integer is used for the page parameter for a search URL, the search query will use a negative number for the LIMIT clause. This causes the query to break, showing no results. It IS NOT however a sql injection error.” While the original report is from a researcher with mixed accuracy, as of 20060703, CVE does not have any additional information regarding this issue

Affected configurations

NVD
Node
phorumphorumRange5.1.14
CPENameOperatorVersion
phorum:phorumphorumle5.1.14

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.5 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

79.5%

Related for CVE-2006-3249