VulnerabilityModified
CVE-2006-2826
SQL injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a allows remote attackers to execute arbitrary SQL commands via the id variable, which is set by a client through a query string or a cookie.
HIGH 7.5EPSS 3.12%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.12%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SQL injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a allows remote attackers to execute arbitrary SQL commands via the id variable, which is set by a client through a query string or a cookie.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 3.12% probability · 87th percentile
- CISA KEV
- Not listed
- Affected
- phplib team/phplib
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/16902Patch, Vendor Advisory
- http://securitytracker.com/id?1016123Patch
- http://sourceforge.net/project/shownotes.php?group_id=31885&release_id=396091Patch
- http://www.gulftech.org/?node=research&article_id=00107-03052006Vendor Advisory
- http://www.osvdb.org/23466Patch
- http://www.securityfocus.com/bid/16801Patch
- http://www.vupen.com/english/advisories/2006/0720
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24873
- http://secunia.com/advisories/16902Patch, Vendor Advisory
- http://securitytracker.com/id?1016123Patch
- http://sourceforge.net/project/shownotes.php?group_id=31885&release_id=396091Patch
- http://www.gulftech.org/?node=research&article_id=00107-03052006Vendor Advisory
- http://www.osvdb.org/23466Patch
- http://www.securityfocus.com/bid/16801Patch
- http://www.vupen.com/english/advisories/2006/0720
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24873
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.