CVE-2006-0123 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 3.2% (pctl 88)
Patch early
A public exploit exists.
Description
Multiple SQL injection vulnerabilities in ADN Forum 1.0b allow remote attackers to execute arbitrary SQL commands via the (1) fid parameter in index.php and (2) pagid parameter in verpag.php, and possibly other vectors.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 3.24% — more likely to be exploited than 88% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-01-09 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| adn forum | adn forum |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | ADN Forum 1.0b - Blind SQL Injection | 2008-10-01 |
References
- http://evuln.com/vulns/15/summary.html
- http://secunia.com/advisories/18300
- http://securitytracker.com/id?1015445
- http://www.osvdb.org/22240
- http://www.osvdb.org/22241
- http://www.securityfocus.com/archive/1/420990/100/0/threaded
- http://www.securityfocus.com/bid/16157
- http://www.vupen.com/english/advisories/2006/0077
- http://evuln.com/vulns/15/summary.html
- http://secunia.com/advisories/18300
- http://securitytracker.com/id?1015445
- http://www.osvdb.org/22240
- http://www.osvdb.org/22241
- http://www.securityfocus.com/archive/1/420990/100/0/threaded
- http://www.securityfocus.com/bid/16157
- http://www.vupen.com/english/advisories/2006/0077
→ the Explorer · watch your stack · NVD