VulnerabilityModified
CVE-2006-1481
SQL injection vulnerability in search.php in PHP Ticket 0.71 allows remote authenticated users to execute arbitrary SQL commands and obtain usernames and passwords via the frm_search_in parameter.
MEDIUM 6.5EPSS 1.00%
Does this matter?
Lower severity and a low EPSS score (1.00%). Track it; it rarely justifies an emergency change on its own.
Description
SQL injection vulnerability in search.php in PHP Ticket 0.71 allows remote authenticated users to execute arbitrary SQL commands and obtain usernames and passwords via the frm_search_in parameter.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.00% probability · 61th percentile
- CISA KEV
- Not listed
- Affected
- php ticket/php ticket
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/19412Exploit
- http://www.securityfocus.com/bid/17229Exploit
- http://www.vupen.com/english/advisories/2006/1106
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25436
- https://www.exploit-db.com/exploits/1609
- http://secunia.com/advisories/19412Exploit
- http://www.securityfocus.com/bid/17229Exploit
- http://www.vupen.com/english/advisories/2006/1106
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25436
- https://www.exploit-db.com/exploits/1609
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.