CVE-2006-3283

critical

Description

SQL injection vulnerability in Dating Agent PRO 4.7.1 allows remote attackers to execute arbitrary SQL commands via the (1) pid parameter in picture.php, (2) mid parameter in mem.php, and the (3) sex and (4) relationship parameters in search.php.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/27342

http://www.securityfocus.com/archive/1/438160/100/100/threaded

http://securityreason.com/securityalert/1164

Details

Source: Mitre, NVD

Published: 2006-06-28

Updated: 2026-04-16

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.00468