Lucene search

K
cve[email protected]CVE-2006-5635
HistoryNov 01, 2006 - 12:07 a.m.

CVE-2006-5635

2006-11-0100:07:00
web.nvd.nist.gov
24
sql injection
vulnerability
forum
search
web wiz forums
remote attackers
sql commands
kw parameter

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.8 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

55.8%

SQL injection vulnerability in forum/search.asp in Web Wiz Forums allows remote attackers to execute arbitrary SQL commands via the KW parameter.

Affected configurations

NVD
Node
web_wiz_forumsweb_wiz_forumsMatch6.34
OR
web_wiz_forumsweb_wiz_forumsMatch7.0
OR
web_wiz_forumsweb_wiz_forumsMatch7.0.1
OR
web_wiz_forumsweb_wiz_forumsMatch7.0_beta1
OR
web_wiz_forumsweb_wiz_forumsMatch7.5
OR
web_wiz_forumsweb_wiz_forumsMatch7.7a
OR
web_wiz_forumsweb_wiz_forumsMatch7.7b
OR
web_wiz_forumsweb_wiz_forumsMatch7.8
OR
web_wiz_forumsweb_wiz_forumsMatch7.9
OR
web_wiz_forumsweb_wiz_forumsMatch7.51
OR
web_wiz_forumsweb_wiz_forumsMatch7.91
OR
web_wiz_forumsweb_wiz_forumsMatch8.0_alpha
OR
web_wiz_forumsweb_wiz_forumsMatch8.04

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.8 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

55.8%

Related for CVE-2006-5635