CVE-2006-0570
Multiple SQL injection vulnerabilities in phpstatus 1.0, when gpc_magic_quotes is disabled, allow remote attackers to execute arbitrary SQL commands and bypass authentication via (1) the username parameter in check.php and (2) unknown attack vectors in…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.45%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple SQL injection vulnerabilities in phpstatus 1.0, when gpc_magic_quotes is disabled, allow remote attackers to execute arbitrary SQL commands and bypass authentication via (1) the username parameter in check.php and (2) unknown attack vectors in the administrative interface.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.45% probability · 72th percentile
- CISA KEV
- Not listed
- Affected
- hinton design/phpstatus
- Source
- cve@mitre.org
References
- http://evuln.com/vulns/61/summary.htmlVendor Advisory
- http://secunia.com/advisories/18791
- http://securityreason.com/securityalert/427
- http://www.securityfocus.com/archive/1/424842/100/0/threaded
- http://www.securityfocus.com/bid/16587
- http://www.vupen.com/english/advisories/2006/0450
- http://evuln.com/vulns/61/summary.htmlVendor Advisory
- http://secunia.com/advisories/18791
- http://securityreason.com/securityalert/427
- http://www.securityfocus.com/archive/1/424842/100/0/threaded
- http://www.securityfocus.com/bid/16587
- http://www.vupen.com/english/advisories/2006/0450
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.