PoC Index

CVE-2006-6161

HIGH 7.5EPSS 1.3%

Multiple SQL injection vulnerabilities in Doug Luxem Liberum Help Desk 0.97.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) uid parameter to (a) inout/status.asp, (b) inout/update.asp, and (c) forgotpass.asp. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
1.29% chance of exploitation in the next 30 days, 68th percentile
Published
2006-11-28
Updated
2024-08-07

Proof-of-concept exploits (1)

References

Related