CVE-2006-0146
The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to execute arbitrary SQL commands via the sql parameter.
- Affected products
- Adodb, Cacti, Maxdev Md-Pro, Mantis, Mediabeez, Moodle, Mysql Server, Phpopenchat
- John Lim Adodb
- = 4.66, 4.68
- Mantis
- = 0.19.4, 1.0.0_rc4
- Mediabeez
- All versions
- Moodle
- = 1.5.3
- Postnuke Software Foundation Postnuke
- = 0.761
- The Cacti Group Cacti
- = 0.8.6g
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 13.2% (96th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2006-01-09
CVE-2006-0146 at NVD
1 known exploit for CVE-2006-0146
Proof-of-concept code and exploit modules indexed by Sploitus