PoC Index

CVE-2006-0146

HIGH 7.5EPSS 13.2%

The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to execute arbitrary SQL commands via the sql parameter.

CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
13.24% chance of exploitation in the next 30 days, 96th percentile
Published
2006-01-09
Updated
2024-08-07

ExploitDB entries (1)

References

Related