CVE-2006-2720
UnknownEPSS 1.18%
Last modified
CVE-2006-2720 is a vulnerability of currently unknown severity. SQL injection vulnerability in news.php in VARIOMAT allows remote attackers to execute arbitrary SQL commands via the subcat parameter.. EPSS estimates a 1.18% chance of exploitation in the next 30 days.
Description
SQL injection vulnerability in news.php in VARIOMAT allows remote attackers to execute arbitrary SQL commands via the subcat parameter.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Variomat | Variomat | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-2720?
SQL injection vulnerability in news.php in VARIOMAT allows remote attackers to execute arbitrary SQL commands via the subcat parameter.
How severe is CVE-2006-2720?
Severity scoring for CVE-2006-2720 is pending analysis. The EPSS model estimates a 1.18% probability of exploitation in the next 30 days.
How do I fix CVE-2006-2720?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2006
- CVE-2006-2714Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1…
- CVE-2006-2715The Administration Console in Secure Elements Class 5 AVR (a…
- CVE-2006-2716Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1…
- CVE-2006-2717Unspecified vulnerability in Secure Elements Class 5 AVR cli…
- CVE-2006-2718JIWA Financials 6.4.14 passes a Microsoft SQL Server account…
- CVE-2006-2719JIWA Financials 6.4.14 stores usernames and passwords for al…
- CVE-2006-2721Cross-site scripting (XSS) vulnerability in news.php in VARI…
- CVE-2006-2722SQL injection vulnerability in view_album.php in SelectaPix …
- CVE-2006-2723Unspecified versions of Mozilla Firefox allow remote attacke…
- CVE-2006-2724Cross-site scripting (XSS) vulnerability in PunBB 1.2.11 all…
- CVE-2006-2725SQL injection vulnerability in rss/posts.php in Eggblog befo…
- CVE-2006-2726PHP remote file inclusion vulnerability in Fastpublish CMS 1…
Are you affected by CVE-2006-2720?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
