VulnerabilityModified
CVE-2006-1641
Multiple SQL injection vulnerabilities in CzarNews 1.14 allow remote attackers to execute arbitrary SQL commands via the (1) usern or (2) passw parameters to (a) cn_auth.php, (3) s parameter to (b) news.php, or (4) a parameter to (c) dpost.php.
MEDIUM 5.1EPSS 2.31%
Does this matter?
Lower severity and a low EPSS score (2.31%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple SQL injection vulnerabilities in CzarNews 1.14 allow remote attackers to execute arbitrary SQL commands via the (1) usern or (2) passw parameters to (a) cn_auth.php, (3) s parameter to (b) news.php, or (4) a parameter to (c) dpost.php.
- CVSS 2.0
- 5.1 MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
- EPSS
- 2.31% probability · 82th percentile
- CISA KEV
- Not listed
- Affected
- czaries network/czarnews
- Source
- cve@mitre.org
References
- http://evuln.com/vulns/118/summary.html
- http://secunia.com/advisories/19541Vendor Advisory
- http://securitytracker.com/id?1015957
- http://www.osvdb.org/24382
- http://www.osvdb.org/24383
- http://www.osvdb.org/24384
- http://www.securityfocus.com/archive/1/431132/100/0/threaded
- http://www.securityfocus.com/bid/17380
- http://www.vupen.com/english/advisories/2006/1237
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25624
- http://evuln.com/vulns/118/summary.html
- http://secunia.com/advisories/19541Vendor Advisory
- http://securitytracker.com/id?1015957
- http://www.osvdb.org/24382
- http://www.osvdb.org/24383
- http://www.osvdb.org/24384
- http://www.securityfocus.com/archive/1/431132/100/0/threaded
- http://www.securityfocus.com/bid/17380
- http://www.vupen.com/english/advisories/2006/1237
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25624
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.