VulnerabilityModified
CVE-2006-3752
Multiple SQL injection vulnerabilities in class.php in Professional Home Page Tools Guestbook allow remote attackers to execute arbitrary SQL commands via the (1) hidemail, (2) name, (3) mail, (4) ip, or (5) text parameters.
HIGH 7.5EPSS 1.53%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.53%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple SQL injection vulnerabilities in class.php in Professional Home Page Tools Guestbook allow remote attackers to execute arbitrary SQL commands via the (1) hidemail, (2) name, (3) mail, (4) ip, or (5) text parameters.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.53% probability · 73th percentile
- CISA KEV
- Not listed
- Affected
- professional home page tools/professional home page tools guestbook
- Source
- cve@mitre.org
References
- http://artemis.abenteuer-mittelerde.de/pub/adv02-phptgb.txtExploit
- http://secunia.com/advisories/21102Patch, Vendor Advisory
- http://securityreason.com/securityalert/1248
- http://securitytracker.com/id?1016550
- http://www.securityfocus.com/archive/1/440421/100/0/threaded
- http://www.securityfocus.com/bid/19019
- http://www.vupen.com/english/advisories/2006/2876
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27774
- http://artemis.abenteuer-mittelerde.de/pub/adv02-phptgb.txtExploit
- http://secunia.com/advisories/21102Patch, Vendor Advisory
- http://securityreason.com/securityalert/1248
- http://securitytracker.com/id?1016550
- http://www.securityfocus.com/archive/1/440421/100/0/threaded
- http://www.securityfocus.com/bid/19019
- http://www.vupen.com/english/advisories/2006/2876
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27774
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.