Lucene search

K
cveMitreCVE-2006-6835
HistoryJan 01, 2007 - 11:00 p.m.

CVE-2006-6835

2007-01-0123:00:00
mitre
web.nvd.nist.gov
39
cve-2006-6835
sql injection
neocrome land down under
ldu
security vulnerability
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.8

Confidence

Low

EPSS

0.003

Percentile

70.8%

SQL injection vulnerability in Journal.inc.php in Neocrome Land Down Under (LDU) 8.x and earlier allows remote attackers to execute arbitrary SQL commands via the w parameter to journal.php.

Affected configurations

Nvd
Node
neocromeland_down_underMatch800
OR
neocromeland_down_underMatch801
OR
neocromeland_down_underMatch802
VendorProductVersionCPE
neocromeland_down_under800cpe:2.3:a:neocrome:land_down_under:800:*:*:*:*:*:*:*
neocromeland_down_under801cpe:2.3:a:neocrome:land_down_under:801:*:*:*:*:*:*:*
neocromeland_down_under802cpe:2.3:a:neocrome:land_down_under:802:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.8

Confidence

Low

EPSS

0.003

Percentile

70.8%

Related for CVE-2006-6835