CVE-2006-4748
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple SQL injection vulnerabilities in F-ART BLOG:CMS 4.1 allow remote attackers to execute arbitrary SQL commands via the (1) xagent, (2) xpath, (3) xreferer, and (4) xdns parameters in (a) admin/plugins/NP_Log.php, and the (5) pitem parameter in (b) admin/plugins/NP_Poll.php; and allow remote authenticated users to execute arbitrary SQL commands via the (6) pageRef parameter in (c) admin/plugins/NP_Referrer.php.
Múltiples vulnerabilidades de inyección SQL en F-ART BLOG:CMS 4.1, permite a un atacante remoto ejecutar comandos SQL de su eleccióna través de lso parámetros 1) xagent, (2) xpath, (3) xreferer, y (4) xdnsen en (a) admin/plugins/NP_Log.php, y el parámetro pitem en (b)admin/plugins/NP_Poll.php; y permite a un usuario remoto validado ejecutar comandos SQL de su elección a través del parámetro (6)pageRef en (c)admin/plugins/NP_Referrer.php.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2006-09-13 CVE Reserved
- 2006-09-13 CVE Published
- 2024-08-03 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://blogcms.com/wiki/changelog | X_refsource_confirm | |
http://secunia.com/advisories/21808 | Third Party Advisory | |
http://securityreason.com/securityalert/1566 | Third Party Advisory | |
http://www.hackers.ir/advisories/blogcms.html | X_refsource_misc | |
http://www.osvdb.org/28604 | Vdb Entry | |
http://www.osvdb.org/28605 | Vdb Entry | |
http://www.osvdb.org/28606 | Vdb Entry | |
http://www.securityfocus.com/archive/1/445538/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/19909 | Vdb Entry | |
http://www.vupen.com/english/advisories/2006/3521 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/28808 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
F-art Agency Search vendor "F-art Agency" | Blog Cms Search vendor "F-art Agency" for product "Blog Cms" | 4.1 Search vendor "F-art Agency" for product "Blog Cms" and version "4.1" | - |
Affected
|