VulnerabilityModified
CVE-2006-1118
SQL injection vulnerability in bmail before Aardvark PR9.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors involving GBK character sets.
MEDIUM 5.0EPSS 1.15%
Does this matter?
Lower severity and a low EPSS score (1.15%). Track it; it rarely justifies an emergency change on its own.
Description
SQL injection vulnerability in bmail before Aardvark PR9.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors involving GBK character sets.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 1.15% probability · 65th percentile
- CISA KEV
- Not listed
- Affected
- bmail/bmail
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/19147Patch, Vendor Advisory
- http://sourceforge.net/project/shownotes.php?group_id=144412&release_id=399256Patch
- http://www.vupen.com/english/advisories/2006/0863
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25073
- http://secunia.com/advisories/19147Patch, Vendor Advisory
- http://sourceforge.net/project/shownotes.php?group_id=144412&release_id=399256Patch
- http://www.vupen.com/english/advisories/2006/0863
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25073
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.