CVE-2006-2065

UnknownEPSS 1.71%

Last modified

CVE-2006-2065 is a vulnerability of currently unknown severity. SQL injection vulnerability in save.php in PHPSurveyor 0.995 and earlier allows remote attackers to execute arbitrary SQL commands via the surveyid cookie. NOTE: this issue could be leveraged to execute arbitrary PHP code, as demonstrated by inserting directory traversal sequences into the database, which are then processed by the thissurvey['language'] variable.. EPSS estimates a 1.71% chance of exploitation in the next 30 days.

Description

SQL injection vulnerability in save.php in PHPSurveyor 0.995 and earlier allows remote attackers to execute arbitrary SQL commands via the surveyid cookie. NOTE: this issue could be leveraged to execute arbitrary PHP code, as demonstrated by inserting directory traversal sequences into the database, which are then processed by the thissurvey['language'] variable.

Metrics

EPSS Probability
1.71%

74.4th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
PhpsurveyorPhpsurveyor0.96_beta
PhpsurveyorPhpsurveyor0.97_beta
PhpsurveyorPhpsurveyor0.98_beta
PhpsurveyorPhpsurveyor0.98_stable
PhpsurveyorPhpsurveyor0.99
PhpsurveyorPhpsurveyor0.991
PhpsurveyorPhpsurveyor0.992
PhpsurveyorPhpsurveyor0.993
PhpsurveyorPhpsurveyor0.995

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2006-2065?
SQL injection vulnerability in save.php in PHPSurveyor 0.995 and earlier allows remote attackers to execute arbitrary SQL commands via the surveyid cookie. NOTE: this issue could be leveraged to execute arbitrary PHP code, as demonstrated by inserting directory traversal sequences into the database, which are then processed by the thissurvey['language'] variable.
How severe is CVE-2006-2065?
Severity scoring for CVE-2006-2065 is pending analysis. The EPSS model estimates a 1.71% probability of exploitation in the next 30 days.
How do I fix CVE-2006-2065?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2006-2065?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST