peter bassill · operator
$ cve CVE-2006-0146 JSON

CVE-2006-0146 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 13.2% (pctl 96)

Patch early

A public exploit exists.

Description

The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to execute arbitrary SQL commands via the sql parameter.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS13.24% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2006-01-09
Last modified2026-06-16

Affected (6)

VendorProduct
john limadodb
mantismantis
mediabeezmediabeez
moodlemoodle
postnuke software foundationpostnuke
the cacti groupcacti

Public exploits

SourceTitleDate
exploit-dbSimplog 0.9.2 - 's' Remote Command Execution2006-04-11

References

→ the Explorer  ·  watch your stack  ·  NVD