HIGH · 7.5

CVE-2006-0146

The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8)...

Vulnerability Description

The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to execute arbitrary SQL commands via the sql parameter.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
John LimAdodb4.66
MantisMantis0.19.4
MediabeezMediabeezAll versions
MoodleMoodle1.5.3
Postnuke Software FoundationPostnuke0.761
The Cacti GroupCacti0.8.6g

Related Weaknesses (CWE)

References

FAQ

What is CVE-2006-0146?

CVE-2006-0146 is a vulnerability with a CVSS score of 7.5 (HIGH). The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8)...

How severe is CVE-2006-0146?

CVE-2006-0146 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-0146?

Check the references section above for vendor advisories and patch information. Affected products include: John Lim Adodb, Mantis Mantis, Mediabeez Mediabeez, Moodle Moodle, Postnuke Software Foundation Postnuke.