Описание
SQL injection vulnerability in index.php in DataLife Engine 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via double-encoded values in the user parameter in a userinfo subaction.
SQL injection vulnerability in index.php in DataLife Engine 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via double-encoded values in the user parameter in a userinfo subaction.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2006-3221
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27321
- https://www.exploit-db.com/exploits/1938
- https://www.exploit-db.com/exploits/1939
- http://secunia.com/advisories/20765
- http://www.securityfocus.com/bid/18592
- http://www.vupen.com/english/advisories/2006/2486
EPSS
Процентиль: 86%
0.027
Низкий
CVE ID
Связанные уязвимости
nvd
больше 19 лет назад
SQL injection vulnerability in index.php in DataLife Engine 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via double-encoded values in the user parameter in a userinfo subaction.
EPSS
Процентиль: 86%
0.027
Низкий