CVE-2006-5840
Multiple SQL injection vulnerabilities in Abarcar Realty Portal allow remote attackers to execute arbitrary SQL commands via the (1) neid parameter to newsdetails.php, or the (2) slid parameter to slistl.php.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.08%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple SQL injection vulnerabilities in Abarcar Realty Portal allow remote attackers to execute arbitrary SQL commands via the (1) neid parameter to newsdetails.php, or the (2) slid parameter to slistl.php. NOTE: the cat vector is already covered by CVE-2006-2853. NOTE: the vendor has notified CVE that the current version only creates static pages, and that slistl.php/slid never existed in any version
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.08% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- abarcar/abarcar realty portal
- Source
- cve@mitre.org
References
- http://attrition.org/pipermail/vim/2006-December/001190.htmlMailing List
- http://s-a-p.ca/index.php?page=OurAdvisories&id=7URL Repurposed
- http://secunia.com/advisories/22792Vendor Advisory
- http://securityreason.com/securityalert/1840Third Party Advisory
- http://www.attrition.org/pipermail/vim/2006-December/001170.htmlMailing List
- http://www.osvdb.org/30249Broken Link
- http://www.osvdb.org/30250Broken Link
- http://www.securityfocus.com/archive/1/450946/100/0/threadedThird Party Advisory
- http://www.securityfocus.com/bid/20970Exploit, Patch
- http://www.vupen.com/english/advisories/2006/4418Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30135Third Party Advisory
- http://attrition.org/pipermail/vim/2006-December/001190.htmlMailing List
- http://s-a-p.ca/index.php?page=OurAdvisories&id=7URL Repurposed
- http://secunia.com/advisories/22792Vendor Advisory
- http://securityreason.com/securityalert/1840Third Party Advisory
- http://www.attrition.org/pipermail/vim/2006-December/001170.htmlMailing List
- http://www.osvdb.org/30249Broken Link
- http://www.osvdb.org/30250Broken Link
- http://www.securityfocus.com/archive/1/450946/100/0/threadedThird Party Advisory
- http://www.securityfocus.com/bid/20970Exploit, Patch
- http://www.vupen.com/english/advisories/2006/4418Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30135Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.