CVE-2006-0823
Multiple SQL injection vulnerabilities in Geeklog 1.4.0 before 1.4.0sr1 and 1.3.11 before 1.3.11sr4 allow remote attackers to inject arbitrary SQL commands via the (1) userid variable to users.php or (2) sessid variable to lib-sessions.php.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.67%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple SQL injection vulnerabilities in Geeklog 1.4.0 before 1.4.0sr1 and 1.3.11 before 1.3.11sr4 allow remote attackers to inject arbitrary SQL commands via the (1) userid variable to users.php or (2) sessid variable to lib-sessions.php.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.67% probability · 75th percentile
- CISA KEV
- Not listed
- Affected
- geeklog/geeklog
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/18920Patch, Vendor Advisory
- http://www.geeklog.net/article.php/geeklog-1.4.0sr1
- http://www.gulftech.org/?node=research&article_id=00102-02192006
- http://www.osvdb.org/23348
- http://www.securityfocus.com/archive/1/425506/100/0/threaded
- http://www.securityfocus.com/bid/16755
- http://www.vupen.com/english/advisories/2006/0661
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24775
- http://secunia.com/advisories/18920Patch, Vendor Advisory
- http://www.geeklog.net/article.php/geeklog-1.4.0sr1
- http://www.gulftech.org/?node=research&article_id=00102-02192006
- http://www.osvdb.org/23348
- http://www.securityfocus.com/archive/1/425506/100/0/threaded
- http://www.securityfocus.com/bid/16755
- http://www.vupen.com/english/advisories/2006/0661
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24775
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.