6.5
CVSSv2

CVE-2006-3828

Published: 25/07/2006 Updated: 17/10/2018
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Incomplete blacklist vulnerability in Kailash Nadh boastMachine (formerly bMachine) 3.1 and previous versions allows remote authenticated administrators to bypass SQL injection protection mechanisms by using commas, quote characters, pound sign (#) characters, "UNION," and "SELECT," which are not filtered by the product, which only checks for "insert," "delete," "update," and "replace."

Vulnerable Product Search on Vulmon Subscribe to Product

kailash nadh boastmachine 2.7

kailash nadh boastmachine 2.8

kailash nadh boastmachine 2.9b

kailash nadh boastmachine 3.1

kailash nadh boastmachine 2.5