CVE-2006-0146
Detail
Deferred
This CVE record is not being prioritized for NVD enrichment efforts due to resource or other concerns.
Current Description
The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to execute arbitrary SQL commands via the sql parameter.
View Analysis Description
Analysis
Description
The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, and (4) Cacti, (5) Xaraya, (6) PHPOpenChat, and (7) MAXdev MD-Pro, and when the MySQL root password is empty, allows remote attackers to execute arbitrary SQL statements via the sql parameter.
Metrics
CVSS Version 4.0
CVSS Version 3.x
CVSS Version 2.0
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
CVSS 4.0 Severity and Vector Strings:
NVD assessment
not yet provided.
CVSS 3.x Severity and Vector Strings:
NVD assessment
not yet provided.
CVSS 2.0 Severity and Vector Strings:
Vector:
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [email protected] .
URL
Source(s)
Tag(s)
http://retrogod.altervista.org/phpopenchat_30x_sql_xpl.html
CVE, MITRE
Exploit
http://secunia.com/advisories/17418
CVE, MITRE
Exploit
Patch
Vendor Advisory
http://secunia.com/advisories/18233
CVE, MITRE
Patch
Vendor Advisory
http://secunia.com/advisories/18254
CVE, MITRE
Vendor Advisory
http://secunia.com/advisories/18260
CVE, MITRE
Patch
Vendor Advisory
http://secunia.com/advisories/18267
CVE, MITRE
Vendor Advisory
http://secunia.com/advisories/18276
CVE, MITRE
Patch
Vendor Advisory
http://secunia.com/advisories/18720
CVE, MITRE
Patch
Vendor Advisory
http://secunia.com/advisories/19555
CVE, MITRE
Patch
Vendor Advisory
http://secunia.com/advisories/19563
CVE, MITRE
Patch
Vendor Advisory
http://secunia.com/advisories/19590
CVE, MITRE
Patch
Vendor Advisory
http://secunia.com/advisories/19591
CVE, MITRE
Patch
Vendor Advisory
http://secunia.com/advisories/19600
CVE, MITRE
Vendor Advisory
http://secunia.com/advisories/19691
CVE, MITRE
Vendor Advisory
http://secunia.com/advisories/19699
CVE, MITRE
Patch
Vendor Advisory
http://secunia.com/advisories/24954
CVE, MITRE
Vendor Advisory
http://secunia.com/secunia_research/2005-64/advisory/
CVE, MITRE
Exploit
Patch
Vendor Advisory
http://securityreason.com/securityalert/713
CVE, MITRE
http://www.debian.org/security/2006/dsa-1029
CVE, MITRE
Patch
Vendor Advisory
http://www.debian.org/security/2006/dsa-1030
CVE, MITRE
Patch
Vendor Advisory
http://www.debian.org/security/2006/dsa-1031
CVE, MITRE
Patch
Vendor Advisory
http://www.gentoo.org/security/en/glsa/glsa-200604-07.xml
CVE, MITRE
Patch
Vendor Advisory
http://www.maxdev.com/Article550.phtml
CVE, MITRE
URL Repurposed
http://www.osvdb.org/22290
CVE, MITRE
Exploit
Patch
http://www.securityfocus.com/archive/1/423784/100/0/threaded
CVE, MITRE
http://www.securityfocus.com/archive/1/430448/100/0/threaded
CVE, MITRE
http://www.securityfocus.com/archive/1/466171/100/0/threaded
CVE, MITRE
http://www.securityfocus.com/bid/16187
CVE, MITRE
Exploit
Patch
http://www.vupen.com/english/advisories/2006/0101
CVE, MITRE
Vendor Advisory
http://www.vupen.com/english/advisories/2006/0102
CVE, MITRE
http://www.vupen.com/english/advisories/2006/0103
CVE, MITRE
Vendor Advisory
http://www.vupen.com/english/advisories/2006/0104
CVE, MITRE
Vendor Advisory
http://www.vupen.com/english/advisories/2006/0105
CVE, MITRE
Vendor Advisory
http://www.vupen.com/english/advisories/2006/0370
CVE, MITRE
Vendor Advisory
http://www.vupen.com/english/advisories/2006/0447
CVE, MITRE
Vendor Advisory
http://www.vupen.com/english/advisories/2006/1304
CVE, MITRE
Vendor Advisory
http://www.vupen.com/english/advisories/2006/1305
CVE, MITRE
Vendor Advisory
http://www.vupen.com/english/advisories/2006/1419
CVE, MITRE
http://www.xaraya.com/index.php/news/569
CVE, MITRE
Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/24051
CVE, MITRE
Weakness Enumeration
CWE-ID
CWE Name
Source
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
NIST
Change History
6 change records found show changes
CVE Modified by CVE 11/20/2024 7:05:45 PM
Action
Type
Old Value
New Value
Added
Reference
http://retrogod.altervista.org/phpopenchat_30x_sql_xpl.html
Added
Reference
http://secunia.com/advisories/17418
Added
Reference
http://secunia.com/advisories/18233
Added
Reference
http://secunia.com/advisories/18254
Added
Reference
http://secunia.com/advisories/18260
Added
Reference
http://secunia.com/advisories/18267
Added
Reference
http://secunia.com/advisories/18276
Added
Reference
http://secunia.com/advisories/18720
Added
Reference
http://secunia.com/advisories/19555
Added
Reference
http://secunia.com/advisories/19563
Added
Reference
http://secunia.com/advisories/19590
Added
Reference
http://secunia.com/advisories/19591
Added
Reference
http://secunia.com/advisories/19600
Added
Reference
http://secunia.com/advisories/19691
Added
Reference
http://secunia.com/advisories/19699
Added
Reference
http://secunia.com/advisories/24954
Added
Reference
http://secunia.com/secunia_research/2005-64/advisory/
Added
Reference
http://securityreason.com/securityalert/713
Added
Reference
http://www.debian.org/security/2006/dsa-1029
Added
Reference
http://www.debian.org/security/2006/dsa-1030
Added
Reference
http://www.debian.org/security/2006/dsa-1031
Added
Reference
http://www.gentoo.org/security/en/glsa/glsa-200604-07.xml
Added
Reference
http://www.maxdev.com/Article550.phtml
Added
Reference
http://www.osvdb.org/22290
Added
Reference
http://www.securityfocus.com/archive/1/423784/100/0/threaded
Added
Reference
http://www.securityfocus.com/archive/1/430448/100/0/threaded
Added
Reference
http://www.securityfocus.com/archive/1/466171/100/0/threaded
Added
Reference
http://www.securityfocus.com/bid/16187
Added
Reference
http://www.vupen.com/english/advisories/2006/0101
Added
Reference
http://www.vupen.com/english/advisories/2006/0102
Added
Reference
http://www.vupen.com/english/advisories/2006/0103
Added
Reference
http://www.vupen.com/english/advisories/2006/0104
Added
Reference
http://www.vupen.com/english/advisories/2006/0105
Added
Reference
http://www.vupen.com/english/advisories/2006/0370
Added
Reference
http://www.vupen.com/english/advisories/2006/0447
Added
Reference
http://www.vupen.com/english/advisories/2006/1304
Added
Reference
http://www.vupen.com/english/advisories/2006/1305
Added
Reference
http://www.vupen.com/english/advisories/2006/1419
Added
Reference
http://www.xaraya.com/index.php/news/569
Added
Reference
https://exchange.xforce.ibmcloud.com/vulnerabilities/24051
CVE Modified by MITRE 5/13/2024 9:34:02 PM
Action
Type
Old Value
New Value
Reference Tag Update by NIST 2/13/2024 8:17:43 PM
Action
Type
Old Value
New Value
Changed
Reference Type
http://www.maxdev.com/Article550.phtml No Types Assigned
http://www.maxdev.com/Article550.phtml URL Repurposed
CVE Modified by MITRE 10/19/2018 11:42:50 AM
Action
Type
Old Value
New Value
Added
Reference
http://www.securityfocus.com/archive/1/423784/100/0/threaded [No Types Assigned]
Added
Reference
http://www.securityfocus.com/archive/1/430448/100/0/threaded [No Types Assigned]
Added
Reference
http://www.securityfocus.com/archive/1/466171/100/0/threaded [No Types Assigned]
Removed
Reference
http://www.securityfocus.com/archive/1/archive/1/423784/100/0/threaded [Patch]
Removed
Reference
http://www.securityfocus.com/archive/1/archive/1/430448/100/0/threaded [Exploit]
Removed
Reference
http://www.securityfocus.com/archive/1/archive/1/466171/100/0/threaded [No Types Assigned]
CVE Modified by MITRE 7/19/2017 9:29:29 PM
Action
Type
Old Value
New Value
Added
Reference
https://exchange.xforce.ibmcloud.com/vulnerabilities/24051 [No Types Assigned]
Removed
Reference
http://xforce.iss.net/xforce/xfdb/24051 [No Types Assigned]
Initial CVE Analysis 1/10/2006 8:39:00 AM
Action
Type
Old Value
New Value
Quick Info
CVE Dictionary Entry: CVE-2006-0146 NVD
Published Date: 01/09/2006 NVD
Last Modified: 04/02/2025
Source: MITRE