Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-1278

Опубликовано: 19 мар. 2006
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

SQL injection vulnerability in @1 File Store 2006.03.07 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) functions.php and (2) user.php in the libs directory, (3) edit.php and (4) delete.php in control/files/, (5) edit.php and (6) delete.php in control/users/, (7) edit.php, (8) access.php, and (9) in control/folders/, (10) access.php and (11) delete.php in control/groups/, (12) confirm.php, and (13) download.php; (14) the email parameter in password.php, and (15) the id parameter in folder.php. NOTE: it was later reported that vectors 12 and 13 also affect @1 File Store PRO 3.2.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:upoint:\@1_file_store:2006.03.07:*:*:*:*:*:*:*

EPSS

Процентиль: 85%
0.02625
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-89

Связанные уязвимости

github
почти 4 года назад

SQL injection vulnerability in @1 File Store 2006.03.07 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) functions.php and (2) user.php in the libs directory, (3) edit.php and (4) delete.php in control/files/, (5) edit.php and (6) delete.php in control/users/, (7) edit.php, (8) access.php, and (9) in control/folders/, (10) access.php and (11) delete.php in control/groups/, (12) confirm.php, and (13) download.php; (14) the email parameter in password.php, and (15) the id parameter in folder.php. NOTE: it was later reported that vectors 12 and 13 also affect @1 File Store PRO 3.2.

EPSS

Процентиль: 85%
0.02625
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-89