CVE-2006-3430
 
Severity Score
7.5
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
SQL injection vulnerability in checkprofile.asp in (1) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1 and (2) Novell ZENworks 6.2 SR1 and earlier, allows remote attackers to execute arbitrary SQL commands via the agentid parameter.
Vulnerabilidad de inyección SQL en checkprofile.asp de (1) PatchLink Update Server (PLUS) versiones anteriores a 6.1 P1 y 6.2.x versiones anteriores a 6.2 SR1 P1 y (2) Novell ZENworks 6.2 SR1 y versiones anteriores, permite a atacantes remotos ejecutar comandos SQL de su elección a través del parámetro agentid.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2006-07-06 CVE Reserved
- 2006-07-07 CVE Published
- 2024-05-27 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://lists.grok.org.uk/pipermail/full-disclosure/2006-June/047495.html | Mailing List | |
http://securityreason.com/securityalert/1200 | Third Party Advisory | |
http://securitytracker.com/id?1016405 | Vdb Entry | |
http://www.securityfocus.com/archive/1/438710/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/18715 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/27545 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/20876 | 2018-10-18 | |
http://secunia.com/advisories/20878 | 2018-10-18 | |
http://www.vupen.com/english/advisories/2006/2595 | 2018-10-18 | |
http://www.vupen.com/english/advisories/2006/2596 | 2018-10-18 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Lumension Search vendor "Lumension" | Patchlink Update Server Search vendor "Lumension" for product "Patchlink Update Server" | 6.1 Search vendor "Lumension" for product "Patchlink Update Server" and version "6.1" | - |
Affected
| ||||||
Lumension Search vendor "Lumension" | Patchlink Update Server Search vendor "Lumension" for product "Patchlink Update Server" | 6.2.0.181 Search vendor "Lumension" for product "Patchlink Update Server" and version "6.2.0.181" | - |
Affected
| ||||||
Lumension Search vendor "Lumension" | Patchlink Update Server Search vendor "Lumension" for product "Patchlink Update Server" | 6.2.0.189 Search vendor "Lumension" for product "Patchlink Update Server" and version "6.2.0.189" | - |
Affected
| ||||||
Novell Search vendor "Novell" | Zenworks Search vendor "Novell" for product "Zenworks" | <= 6.2 Search vendor "Novell" for product "Zenworks" and version " <= 6.2" | sr1 |
Affected
|