Lucene search

K
cveMitreCVE-2006-3828
HistoryJul 25, 2006 - 1:22 p.m.

CVE-2006-3828

2006-07-2513:22:00
mitre
web.nvd.nist.gov
21
cve-2006-3828
incomplete blacklist vulnerability
kailash nadh boastmachine
bmachine
sql injection
remote authenticated administrators

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

AI Score

7.7

Confidence

Low

EPSS

0.002

Percentile

61.2%

Incomplete blacklist vulnerability in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allows remote authenticated administrators to bypass SQL injection protection mechanisms by using commas, quote characters, pound sign (#) characters, “UNION,” and “SELECT,” which are not filtered by the product, which only checks for “insert,” “delete,” “update,” and “replace.”

Affected configurations

Nvd
Node
kailash_nadhboastmachineMatch2.5
OR
kailash_nadhboastmachineMatch2.7
OR
kailash_nadhboastmachineMatch2.8
OR
kailash_nadhboastmachineMatch2.9b
OR
kailash_nadhboastmachineMatch3.1
VendorProductVersionCPE
kailash_nadhboastmachine2.5cpe:2.3:a:kailash_nadh:boastmachine:2.5:*:*:*:*:*:*:*
kailash_nadhboastmachine2.7cpe:2.3:a:kailash_nadh:boastmachine:2.7:*:*:*:*:*:*:*
kailash_nadhboastmachine2.8cpe:2.3:a:kailash_nadh:boastmachine:2.8:*:*:*:*:*:*:*
kailash_nadhboastmachine2.9bcpe:2.3:a:kailash_nadh:boastmachine:2.9b:*:*:*:*:*:*:*
kailash_nadhboastmachine3.1cpe:2.3:a:kailash_nadh:boastmachine:3.1:*:*:*:*:*:*:*

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

AI Score

7.7

Confidence

Low

EPSS

0.002

Percentile

61.2%

Related for CVE-2006-3828