CVE-2006-0146
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 13%
from disclosure to weapon92 days
Published on NVDJan 9
1st PoC+92d
exploitation probability
13%top 4% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to execute arbitrary SQL commands via the sql parameter.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/1663⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://retrogod.altervista.org/phpopenchat_30x_sql_xpl.htmlhttp://secunia.com/advisories/17418http://secunia.com/advisories/18233http://secunia.com/advisories/18254http://secunia.com/advisories/18260http://secunia.com/advisories/18267http://secunia.com/advisories/18276http://secunia.com/advisories/18720http://secunia.com/advisories/19555http://secunia.com/advisories/19563http://secunia.com/advisories/19590http://secunia.com/advisories/19591