CVE-2006-3860
NISR02082006F.txt
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
IBM Informix Dynamic Server (IDS) before 9.40.xC7 and 10.00 before 10.00.xC3 allows allows remote authenticated users to execute arbitrary commands via the (1) "SET DEBUG FILE" SQL command, and the (2) start_onpload and (3) dbexp functions.
IBM Informix Dynamic Server (IDS) anterior a 9.40.xC7 y 20.00 anterior a 10.00.xC3 permite a usuarios remotos autenticados ejecutar comandos de su elección mediante el comando SQL (1) "SET DEBUG FILE", y las funciones (2)start_onpload y (3) dbexp.
Informix Dynamic Server is a database developed by IBM. During a security assessment of Informix multiple arbitrary command execution flaws were found. It is possible to inject arbitrary operating system commands into the SET DEBUG FILE SQL statement and the start_onpload and dbexp procedures. Any commands injected into SET DEBUG FILE will execute with the privileges of the informix user; any command injected into dbexp or start_onpload will execute with the privileges of the logged on user. All versions are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2006-07-26 CVE Reserved
- 2006-08-17 CVE Published
- 2024-08-07 CVE Updated
- 2025-04-05 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://securityreason.com/securityalert/1407 | Third Party Advisory | |
http://www-1.ibm.com/support/docview.wss?uid=swg21242921 | X_refsource_confirm | |
http://www.databasesecurity.com/informix/DatabaseHackersHandbook-AttackingInformix.pdf | X_refsource_misc | |
http://www.osvdb.org/27686 | Vdb Entry | |
http://www.securityfocus.com/archive/1/443133/100/0/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/443185/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/19264 | Vdb Entry | |
http://www.vupen.com/english/advisories/2006/3077 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/28121 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/28124 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/21301 | 2018-10-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | Informix Dynamic Database Server Search vendor "Ibm" for product "Informix Dynamic Database Server" | 7.3 Search vendor "Ibm" for product "Informix Dynamic Database Server" and version "7.3" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Informix Dynamic Database Server Search vendor "Ibm" for product "Informix Dynamic Database Server" | 7.31_.xd8 Search vendor "Ibm" for product "Informix Dynamic Database Server" and version "7.31_.xd8" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Informix Dynamic Database Server Search vendor "Ibm" for product "Informix Dynamic Database Server" | 9.4 Search vendor "Ibm" for product "Informix Dynamic Database Server" and version "9.4" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Informix Dynamic Database Server Search vendor "Ibm" for product "Informix Dynamic Database Server" | 9.40.tc5 Search vendor "Ibm" for product "Informix Dynamic Database Server" and version "9.40.tc5" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Informix Dynamic Database Server Search vendor "Ibm" for product "Informix Dynamic Database Server" | 9.40.uc1 Search vendor "Ibm" for product "Informix Dynamic Database Server" and version "9.40.uc1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Informix Dynamic Database Server Search vendor "Ibm" for product "Informix Dynamic Database Server" | 9.40.uc2 Search vendor "Ibm" for product "Informix Dynamic Database Server" and version "9.40.uc2" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Informix Dynamic Database Server Search vendor "Ibm" for product "Informix Dynamic Database Server" | 9.40.uc3 Search vendor "Ibm" for product "Informix Dynamic Database Server" and version "9.40.uc3" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Informix Dynamic Database Server Search vendor "Ibm" for product "Informix Dynamic Database Server" | 9.40.uc5 Search vendor "Ibm" for product "Informix Dynamic Database Server" and version "9.40.uc5" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Informix Dynamic Database Server Search vendor "Ibm" for product "Informix Dynamic Database Server" | 9.40.xc7 Search vendor "Ibm" for product "Informix Dynamic Database Server" and version "9.40.xc7" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Informix Dynamic Database Server Search vendor "Ibm" for product "Informix Dynamic Database Server" | 10.0 Search vendor "Ibm" for product "Informix Dynamic Database Server" and version "10.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Informix Dynamic Database Server Search vendor "Ibm" for product "Informix Dynamic Database Server" | 10.0_xc3 Search vendor "Ibm" for product "Informix Dynamic Database Server" and version "10.0_xc3" | - |
Affected
|