Vulnerability Description
SQL injection vulnerability in kategorix.asp in Haberx 1.02 through 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in kategorihaberx.asp.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Haberx | Haberx | 1.0.2 |
References
- http://packetstorm.linuxsecurity.com/0609-exploits/haberx.txt
- http://secunia.com/advisories/21960Vendor Advisory
- http://www.securityfocus.com/bid/20038Exploit
- http://www.vupen.com/english/advisories/2006/3661
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28988
- https://www.exploit-db.com/exploits/2371
- http://packetstorm.linuxsecurity.com/0609-exploits/haberx.txt
- http://secunia.com/advisories/21960Vendor Advisory
- http://www.securityfocus.com/bid/20038Exploit
- http://www.vupen.com/english/advisories/2006/3661
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28988
- https://www.exploit-db.com/exploits/2371
FAQ
What is CVE-2006-4853?
CVE-2006-4853 is a vulnerability with a CVSS score of 7.5 (HIGH). SQL injection vulnerability in kategorix.asp in Haberx 1.02 through 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in kategorihaberx.asp.
How severe is CVE-2006-4853?
CVE-2006-4853 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-4853?
Check the references section above for vendor advisories and patch information. Affected products include: Haberx Haberx.