CVE-2006-6846
Multiple SQL injection vulnerabilities in While You Were Out (WYWO) InOut Board 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the num parameter in (a) phonemessage.asp, (2) the catcode parameter in (b) faqDsp.asp, and the (3)…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.04%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple SQL injection vulnerabilities in While You Were Out (WYWO) InOut Board 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the num parameter in (a) phonemessage.asp, (2) the catcode parameter in (b) faqDsp.asp, and the (3) Username and (4) Password fields in (c) login.asp.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.04% probability · 62th percentile
- CISA KEV
- Not listed
- Affected
- cybercoded/while you were out inout board
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/23571
- http://www.securityfocus.com/bid/21803Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31128
- https://www.exploit-db.com/exploits/3032
- http://secunia.com/advisories/23571
- http://www.securityfocus.com/bid/21803Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31128
- https://www.exploit-db.com/exploits/3032
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.