Sploitus

CVE-2006-0146

1 known exploit for CVE-2006-0146

The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to execute arbitrary SQL commands via the sql parameter.

John Lim Adodb
= 4.66, 4.68
Mantis
= 0.19.4, 1.0.0_rc4
Mediabeez
All versions
Moodle
= 1.5.3
Postnuke Software Foundation Postnuke
= 0.761
The Cacti Group Cacti
= 0.8.6g
Fix
Available
CVSS 2.0
7.5 HIGH
EPSS
13.2% (96th percentile)
Weakness
CWE-89
NVD status
Modified
Published
2006-01-09
CVE-2006-0146 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2006-0146

Proof-of-concept code and exploit modules indexed by Sploitus