VulnerabilityModified
CVE-2006-6147
Multiple SQL injection vulnerabilities in JiRos Links Manager allow remote attackers to execute arbitrary SQL commands via the (1) LinkID parameter to openlink.asp or the (2) CategoryID parameter to viewlinks.asp.
HIGH 7.5EPSS 1.27%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.27%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple SQL injection vulnerabilities in JiRos Links Manager allow remote attackers to execute arbitrary SQL commands via the (1) LinkID parameter to openlink.asp or the (2) CategoryID parameter to viewlinks.asp.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.27% probability · 68th percentile
- CISA KEV
- Not listed
- Affected
- jiros/links manager
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/23063Vendor Advisory
- http://securitytracker.com/id?1017280Vendor Advisory
- http://www.frsirt.com/english/reference-2006-4664-1.phpVendor Advisory
- http://www.securityfocus.com/archive/1/452265/100/0/threaded
- http://www.securityfocus.com/bid/21226Exploit, Vendor Advisory
- http://www.vupen.com/english/advisories/2006/4664
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30462
- http://secunia.com/advisories/23063Vendor Advisory
- http://securitytracker.com/id?1017280Vendor Advisory
- http://www.frsirt.com/english/reference-2006-4664-1.phpVendor Advisory
- http://www.securityfocus.com/archive/1/452265/100/0/threaded
- http://www.securityfocus.com/bid/21226Exploit, Vendor Advisory
- http://www.vupen.com/english/advisories/2006/4664
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30462
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.