Lucene search

K
ubuntucveUbuntu.comUB:CVE-2006-0913
HistoryFeb 28, 2006 - 12:00 a.m.

CVE-2006-0913

2006-02-2800:00:00
ubuntu.com
ubuntu.com
16

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:P/A:P

EPSS

0.003

Percentile

65.9%

SQL injection vulnerability in whineatnews.pl in Bugzilla 2.17 through
2.18.4 and 2.20 allows remote authenticated users with administrative
privileges to execute arbitrary SQL commands via the whinedays parameter,
as accessible from editparams.cgi.

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:P/A:P

EPSS

0.003

Percentile

65.9%