Описание
SQL injection vulnerability in index.php in LifeType 1.0.4 allows remote attackers to execute arbitrary SQL commands via the articleId parameter in a ViewArticle action (viewarticleaction.class.php).
SQL injection vulnerability in index.php in LifeType 1.0.4 allows remote attackers to execute arbitrary SQL commands via the articleId parameter in a ViewArticle action (viewarticleaction.class.php).
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2006-2857
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26916
- http://secunia.com/advisories/20460
- http://securityreason.com/securityalert/1046
- http://www.lifetype.net/blog.php/lifetype_development_journal/2006/06/04/important_security_upgrade_lifetype_1.0.5_released
- http://www.securityfocus.com/archive/1/435874/100/0/threaded
- http://www.securityfocus.com/bid/18264
- http://www.vupen.com/english/advisories/2006/2120
EPSS
Процентиль: 69%
0.01365
Низкий
CVE ID
Связанные уязвимости
nvd
около 20 лет назад
SQL injection vulnerability in index.php in LifeType 1.0.4 allows remote attackers to execute arbitrary SQL commands via the articleId parameter in a ViewArticle action (viewarticleaction.class.php).
EPSS
Процентиль: 69%
0.01365
Низкий