CVE-2006-5217
SQL injection vulnerability in giris_yap.asp in Emek Portal 2.1 allows remote attackers to execute arbitrary SQL commands by simultaneously injecting into the user name and pass fields in uyegiris.asp, also known as the Kullanici Adi (k_a) and Sifre…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.11%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SQL injection vulnerability in giris_yap.asp in Emek Portal 2.1 allows remote attackers to execute arbitrary SQL commands by simultaneously injecting into the user name and pass fields in uyegiris.asp, also known as the Kullanici Adi (k_a) and Sifre (sifre) parameters.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.11% probability · 64th percentile
- CISA KEV
- Not listed
- Affected
- emek portal/emek portal
- Source
- cve@mitre.org
References
- http://securityreason.com/securityalert/1700
- http://www.securityfocus.com/archive/1/447914/100/0/threaded
- http://www.securityfocus.com/bid/20378Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29380
- http://securityreason.com/securityalert/1700
- http://www.securityfocus.com/archive/1/447914/100/0/threaded
- http://www.securityfocus.com/bid/20378Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29380
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.