7.5
CVSSv2

CVE-2006-0517

Published: 02/02/2006 Updated: 19/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in formulaires/inc-formulaire_forum.php3 in SPIP 1.8.2-e and previous versions and 1.9 Alpha 2 (5539) and previous versions allow remote malicious users to execute arbitrary SQL commands via the (1) id_forum, (2) id_article, or (3) id_breve parameters to forum.php3; (4) unspecified vectors related to "session handling"; and (5) when posting "petitions".

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

spip spip

Vendor Advisories

Debian Bug report logs - #351334 CVE-2006-0517: Multiple SQL injection vulnerabilities in SPIP Package: spip; Maintainer for spip is David Prévot <taffit@debianorg>; Source for spip is src:spip (PTS, buildd, popcon) Reported by: Micah Anderson <micah@debianorg> Date: Sat, 4 Feb 2006 05:33:04 UTC Severity: import ...