Описание
Multiple SQL injection vulnerabilities in Core CoreNews 2.0.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) icon_id and (2) userid parameters in preview.php.
Multiple SQL injection vulnerabilities in Core CoreNews 2.0.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) icon_id and (2) userid parameters in preview.php.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2006-2032
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25977
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/045372.html
- http://securityreason.com/securityalert/797
- http://www.nukedx.com/?getxpl=24
- http://www.securityfocus.com/archive/1/431761/100/0/threaded
- http://www.securityfocus.com/bid/17655
EPSS
Процентиль: 77%
0.01073
Низкий
CVE ID
Связанные уязвимости
nvd
почти 20 лет назад
Multiple SQL injection vulnerabilities in Core CoreNews 2.0.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) icon_id and (2) userid parameters in preview.php.
EPSS
Процентиль: 77%
0.01073
Низкий