Описание
Multiple SQL injection vulnerabilities in ActiveNews Manager allow remote attackers to execute arbitrary SQL commands via the (1) articleID parameter to activenews_view.asp or the (2) page parameter to default.asp. NOTE: the activeNews_categories.asp and activeNews_comments.asp vectors are already covered by CVE-2006-6094.
Ссылки
- Mailing List
- Broken Link
- Broken Link
- Broken Link
- ExploitThird Party AdvisoryVDB Entry
- Mailing List
- Broken Link
- Broken Link
- Broken Link
- ExploitThird Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:dotnetindex:active_news_manager:*:*:*:*:*:*:*:*
EPSS
Процентиль: 86%
0.02916
Низкий
7.5 High
CVSS2
Дефекты
CWE-89
Связанные уязвимости
github
почти 4 года назад
Multiple SQL injection vulnerabilities in ActiveNews Manager allow remote attackers to execute arbitrary SQL commands via the (1) articleID parameter to activenews_view.asp or the (2) page parameter to default.asp. NOTE: the activeNews_categories.asp and activeNews_comments.asp vectors are already covered by CVE-2006-6094.
EPSS
Процентиль: 86%
0.02916
Низкий
7.5 High
CVSS2
Дефекты
CWE-89