CVE-2006-3283
SQL injection vulnerability in Dating Agent PRO 4.7.1 allows remote attackers to execute arbitrary SQL commands via the (1) pid parameter in picture.php, (2) mid parameter in mem.php, and the (3) sex and (4) relationship parameters in search.php.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.20%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SQL injection vulnerability in Dating Agent PRO 4.7.1 allows remote attackers to execute arbitrary SQL commands via the (1) pid parameter in picture.php, (2) mid parameter in mem.php, and the (3) sex and (4) relationship parameters in search.php.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.20% probability · 66th percentile
- CISA KEV
- Not listed
- Affected
- datetopia/dating agent pro
- Source
- cve@mitre.org
References
- http://securityreason.com/securityalert/1164
- http://www.securityfocus.com/archive/1/438160/100/100/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27342
- http://securityreason.com/securityalert/1164
- http://www.securityfocus.com/archive/1/438160/100/100/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27342
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.