VulnerabilityModified
CVE-2006-6911
SQL injection vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authenticated users to execute arbitrary SQL commands via the ordernum parameter.
MEDIUM 6.0EPSS 0.90%
Does this matter?
Lower severity and a low EPSS score (0.90%). Track it; it rarely justifies an emergency change on its own.
Description
SQL injection vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authenticated users to execute arbitrary SQL commands via the ordernum parameter.
- CVSS 2.0
- 6.0 MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
- EPSS
- 0.90% probability · 58th percentile
- CISA KEV
- Not listed
- Affected
- digitizing quote and ordering system/digitizing quote and ordering system
- Source
- cve@mitre.org
References
- http://osvdb.org/31689
- http://secunia.com/advisories/23652Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31318
- https://www.exploit-db.com/exploits/3089
- http://osvdb.org/31689
- http://secunia.com/advisories/23652Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31318
- https://www.exploit-db.com/exploits/3089
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.