PoC Index

CVE-2006-6398

HIGH 7.5EPSS 1.1%

Multiple SQL injection vulnerabilities in Superfreaker Studios UPublisher 1.0 allow remote attackers to execute arbitrary SQL commands via unspecified vectors in (a) sendarticle.asp and (b) printarticle.asp, and the ID parameter to (c) index.asp and (d) preferences.asp, different vectors than CVE-2006-5888.

CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
1.05% chance of exploitation in the next 30 days, 62th percentile
Published
2006-12-08
Updated
2024-08-07

Proof-of-concept exploits (1)

References

Related