PoC Index

CVE-2006-1613

MEDIUM 5.0EPSS 1.8%

Multiple SQL injection vulnerabilities in aWebNews 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) user123 variable in (a) login.php or (b) fpass.php; or (2) cid parameter to (c) visview.php.

CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
1.77% chance of exploitation in the next 30 days, 77th percentile
Published
2006-04-04
Updated
2024-08-07

ExploitDB entries (1)

References

Related