VulnerabilityModified
CVE-2006-1001
SQL injection vulnerability in the board module in LanSuite LanParty Intranet System 2.0.6 and 2.1.0 beta allows remote attackers to execute arbitrary SQL commands via the fid parameter.
MEDIUM 5.0EPSS 1.38%
Does this matter?
Lower severity and a low EPSS score (1.38%). Track it; it rarely justifies an emergency change on its own.
Description
SQL injection vulnerability in the board module in LanSuite LanParty Intranet System 2.0.6 and 2.1.0 beta allows remote attackers to execute arbitrary SQL commands via the fid parameter.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 1.38% probability · 71th percentile
- CISA KEV
- Not listed
- Affected
- lansuite/lanparty intranet system
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/19048Vendor Advisory
- http://www.osvdb.org/23533
- http://www.securityfocus.com/bid/16836Exploit, Vendor Advisory
- http://www.vupen.com/english/advisories/2006/0747
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24940
- https://www.exploit-db.com/exploits/1526
- http://secunia.com/advisories/19048Vendor Advisory
- http://www.osvdb.org/23533
- http://www.securityfocus.com/bid/16836Exploit, Vendor Advisory
- http://www.vupen.com/english/advisories/2006/0747
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24940
- https://www.exploit-db.com/exploits/1526
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.