Show plain JSON{"id": "CVE-2006-3244", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 5.1, "accessVector": "NETWORK", "vectorString": "AV:N/AC:H/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "HIGH", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 6.4, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 4.9, "obtainUserPrivilege": false, "obtainOtherPrivilege": true, "userInteractionRequired": false}]}, "published": "2006-06-27T10:05:00.000", "references": [{"url": "http://pridels0.blogspot.com/2006/06/anthill-sql-injection-vuln.html", "source": "cve@mitre.org"}, {"url": "http://secunia.com/advisories/20838", "tags": ["Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "http://www.securityfocus.com/bid/18661", "source": "cve@mitre.org"}, {"url": "http://www.vupen.com/english/advisories/2006/2529", "source": "cve@mitre.org"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27373", "source": "cve@mitre.org"}, {"url": "http://pridels0.blogspot.com/2006/06/anthill-sql-injection-vuln.html", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://secunia.com/advisories/20838", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/bid/18661", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.vupen.com/english/advisories/2006/2529", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27373", "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "NVD-CWE-Other"}]}], "descriptions": [{"lang": "en", "value": "Multiple SQL injection vulnerabilities in Anthill 0.2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) order parameter in buglist.php and the (2) bug parameter in query.php."}, {"lang": "es", "value": "M\u00faltiples vulnerabilidades de inyecci\u00f3n SQL en Anthill v0.2.6 y anteriores permite a atacantes remotos ejecutar comandos SQL a su elecci\u00f3n a trav\u00e9s de (1) el par\u00e1meto \"order\" en buglist.php y (2) el par\u00e1metro \"bug\" en query.php."}], "lastModified": "2025-04-03T01:03:51.193", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:anthill:anthill:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5D7D3015-AAD5-4AD2-B4CD-10C5564426EB", "versionEndIncluding": "0.2.6"}, {"criteria": "cpe:2.3:a:anthill:anthill:0.3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D590F81E-0D93-4BC1-818E-98B4F2750AA7"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}