CVE-2006-0146
The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty,…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.2%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to execute arbitrary SQL commands via the sql parameter.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 13.24% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- john lim/adodb · mantis/mantis · mediabeez/mediabeez · moodle/moodle · postnuke software foundation/postnuke · the cacti group/cacti
- Source
- cve@mitre.org
References
- http://retrogod.altervista.org/phpopenchat_30x_sql_xpl.htmlExploit
- http://secunia.com/advisories/17418Exploit, Patch, Vendor Advisory
- http://secunia.com/advisories/18233Patch, Vendor Advisory
- http://secunia.com/advisories/18254Vendor Advisory
- http://secunia.com/advisories/18260Patch, Vendor Advisory
- http://secunia.com/advisories/18267Vendor Advisory
- http://secunia.com/advisories/18276Patch, Vendor Advisory
- http://secunia.com/advisories/18720Patch, Vendor Advisory
- http://secunia.com/advisories/19555Patch, Vendor Advisory
- http://secunia.com/advisories/19563Patch, Vendor Advisory
- http://secunia.com/advisories/19590Patch, Vendor Advisory
- http://secunia.com/advisories/19591Patch, Vendor Advisory
- http://secunia.com/advisories/19600Vendor Advisory
- http://secunia.com/advisories/19691Vendor Advisory
- http://secunia.com/advisories/19699Patch, Vendor Advisory
- http://secunia.com/advisories/24954Vendor Advisory
- http://secunia.com/secunia_research/2005-64/advisory/Exploit, Patch, Vendor Advisory
- http://securityreason.com/securityalert/713
- http://www.debian.org/security/2006/dsa-1029Patch, Vendor Advisory
- http://www.debian.org/security/2006/dsa-1030Patch, Vendor Advisory
- http://www.debian.org/security/2006/dsa-1031Patch, Vendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200604-07.xmlPatch, Vendor Advisory
- http://www.maxdev.com/Article550.phtmlURL Repurposed
- http://www.osvdb.org/22290Exploit, Patch
- http://www.securityfocus.com/archive/1/423784/100/0/threaded
- http://www.securityfocus.com/archive/1/430448/100/0/threaded
- http://www.securityfocus.com/archive/1/466171/100/0/threaded
- http://www.securityfocus.com/bid/16187Exploit, Patch
- http://www.vupen.com/english/advisories/2006/0101Vendor Advisory
- http://www.vupen.com/english/advisories/2006/0102
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.