CVE-2006-0542

critical

Description

Multiple SQL injection vulnerabilities in config.php in NukedWeb GuestBookHost 2005.04.25 allow remote attackers to execute arbitrary SQL commands via the (1) email and (2) password parameters.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/24406

http://www.vupen.com/english/advisories/2006/0465

http://www.securityfocus.com/bid/16545

http://www.securityfocus.com/archive/1/424714/100/0/threaded

http://www.evuln.com/vulns/56/summary.html

http://secunia.com/advisories/18761

Details

Source: Mitre, NVD

Published: 2006-02-04

Updated: 2026-04-16

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.01311