VulnerabilityModified
CVE-2006-2993
Multiple SQL injection vulnerabilities in My Photo Scrapbook 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the key parameter in (1) Displayview.asp and (2) Details_Photo_bv.asp.
HIGH 7.5EPSS 1.38%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.38%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple SQL injection vulnerabilities in My Photo Scrapbook 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the key parameter in (1) Displayview.asp and (2) Details_Photo_bv.asp.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.38% probability · 71th percentile
- CISA KEV
- Not listed
- Affected
- my photo scrapbook/my photo scrapbook
- Source
- cve@mitre.org
References
- http://pridels0.blogspot.com/2006/06/my-photo-scrapbook-vuln.html
- http://secunia.com/advisories/20554Vendor Advisory
- http://www.osvdb.org/26281
- http://www.osvdb.org/26282
- http://www.securityfocus.com/bid/18418
- http://www.vupen.com/english/advisories/2006/2244
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27087
- http://pridels0.blogspot.com/2006/06/my-photo-scrapbook-vuln.html
- http://secunia.com/advisories/20554Vendor Advisory
- http://www.osvdb.org/26281
- http://www.osvdb.org/26282
- http://www.securityfocus.com/bid/18418
- http://www.vupen.com/english/advisories/2006/2244
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27087
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.