Vulnerability CVE-2006-6846


Published: 2006-12-31   Modified: 2012-02-12

Description:
Multiple SQL injection vulnerabilities in While You Were Out (WYWO) InOut Board 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the num parameter in (a) phonemessage.asp, (2) the catcode parameter in (b) faqDsp.asp, and the (3) Username and (4) Password fields in (c) login.asp.

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Cybercoded -> While you were out inout board 

 References:
http://www.securityfocus.com/bid/21803
https://exchange.xforce.ibmcloud.com/vulnerabilities/31128
https://www.exploit-db.com/exploits/3032

Copyright 2024, cxsecurity.com

 

Back to Top