CVE-2006-6274
Last modified
CVE-2006-6274 is a vulnerability of currently unknown severity. SQL injection vulnerability in articles.asp in Expinion.net iNews (1) Publisher (iNP) 2.5 and earlier, and possibly (2) News Manager, allows remote attackers to execute arbitrary SQL commands via the ex parameter. NOTE: early reports of this issue reported it as XSS, but this was erroneous. EPSS estimates a 2.00% chance of exploitation in the next 30 days.
Description
SQL injection vulnerability in articles.asp in Expinion.net iNews (1) Publisher (iNP) 2.5 and earlier, and possibly (2) News Manager, allows remote attackers to execute arbitrary SQL commands via the ex parameter. NOTE: early reports of this issue reported it as XSS, but this was erroneous. The original report was for News Manager, but there is strong evidence that the correct product is Publisher.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Expinion.Net | Inews Publisher | <= 2.5 |
| Expinion.Net | News Manager | All versions |
References
- http://secunia.com/advisories/23123Vendor Advisory
- http://secunia.com/advisories/23123Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-6274?
How severe is CVE-2006-6274?
How do I fix CVE-2006-6274?
Are you affected by CVE-2006-6274?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
