CVE-2006-0517
EPSS 3.2%
描述
Multiple SQL injection vulnerabilities in formulaires/inc-formulaire_forum.php3 in SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id_forum, (2) id_article, or (3) id_breve parameters to forum.php3; (4) unspecified vectors related to "session handling"; and (5) when posting "petitions".
如何修補 CVE-2006-0517
要修補 CVE-2006-0517,請將受影響套件升級到下列已修補版本。
- Debian/spip—升級至 2.0.6-1 或更新版本
CVE-2006-0517 正在被利用嗎?
低 — EPSS 為 3.2%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 2.0.6-1