VulnerabilityModified
CVE-2006-5150
SQL injection vulnerability in the reports system in OpenBiblio before 0.5.2 allows remote attackers with report privileges to execute arbitrary SQL commands via unspecified vectors.
MEDIUM 6.5EPSS 1.02%
Does this matter?
Lower severity and a low EPSS score (1.02%). Track it; it rarely justifies an emergency change on its own.
Description
SQL injection vulnerability in the reports system in OpenBiblio before 0.5.2 allows remote attackers with report privileges to execute arbitrary SQL commands via unspecified vectors.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.02% probability · 61th percentile
- CISA KEV
- Not listed
- Affected
- openbiblio/openbiblio
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/22238Vendor Advisory
- http://sourceforge.net/project/shownotes.php?release_id=451780Patch
- http://www.securityfocus.com/bid/20301
- http://www.vupen.com/english/advisories/2006/3867
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29318
- http://secunia.com/advisories/22238Vendor Advisory
- http://sourceforge.net/project/shownotes.php?release_id=451780Patch
- http://www.securityfocus.com/bid/20301
- http://www.vupen.com/english/advisories/2006/3867
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29318
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.