CVE-2006-3828
Incomplete blacklist vulnerability in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allows remote authenticated administrators to bypass SQL injection protection mechanisms by using commas, quote characters, pound sign (#) characters,…
Does this matter?
Lower severity and a low EPSS score (1.21%). Track it; it rarely justifies an emergency change on its own.
Description
Incomplete blacklist vulnerability in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allows remote authenticated administrators to bypass SQL injection protection mechanisms by using commas, quote characters, pound sign (#) characters, "UNION," and "SELECT," which are not filtered by the product, which only checks for "insert," "delete," "update," and "replace."
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.21% probability · 67th percentile
- CISA KEV
- Not listed
- Affected
- kailash nadh/boastmachine
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/21066Vendor Advisory
- http://securityreason.com/securityalert/1252
- http://securitytracker.com/id?1016515
- http://www.acid-root.new.fr/advisories/boastmachine.txtExploit
- http://www.securityfocus.com/archive/1/440306/100/0/threaded
- http://www.vupen.com/english/advisories/2006/2849
- http://secunia.com/advisories/21066Vendor Advisory
- http://securityreason.com/securityalert/1252
- http://securitytracker.com/id?1016515
- http://www.acid-root.new.fr/advisories/boastmachine.txtExploit
- http://www.securityfocus.com/archive/1/440306/100/0/threaded
- http://www.vupen.com/english/advisories/2006/2849
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.