VulnerabilityModified
CVE-2006-3115
SQL injection vulnerability in view.php in phpRaid 3.0.4, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via the raid_id parameter.
MEDIUM 5.1EPSS 1.08%
Does this matter?
Lower severity and a low EPSS score (1.08%). Track it; it rarely justifies an emergency change on its own.
Description
SQL injection vulnerability in view.php in phpRaid 3.0.4, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via the raid_id parameter.
- CVSS 2.0
- 5.1 MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
- EPSS
- 1.08% probability · 63th percentile
- CISA KEV
- Not listed
- Affected
- spiffyjr/phpraid
- Source
- PSIRT-CNA@flexerasoftware.com
References
- http://secunia.com/advisories/20200Vendor Advisory
- http://secunia.com/secunia_research/2006-47/advisory/Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27457
- http://secunia.com/advisories/20200Vendor Advisory
- http://secunia.com/secunia_research/2006-47/advisory/Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27457
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.