CVE-2006-3559

critical

Description

Multiple SQL injection vulnerabilities in Arif Supriyanto auraCMS 1.62 allow remote attackers to execute arbitrary SQL commands and delete all shoutbox messages via the (1) name and (2) pesan parameters.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/27705

http://www.securityfocus.com/archive/1/439494/100/0/threaded

http://www.osvdb.org/28201

http://securityreason.com/securityalert/1226

Details

Source: Mitre, NVD

Published: 2006-07-13

Updated: 2026-04-16

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.00851