CVE-2006-0358 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 1.3% (pctl 70)
Patch early
A public exploit exists.
Description
Multiple SQL injection vulnerabilities in PowerPortal, possibly 1.1 beta through 1.3, allow remote attackers to execute arbitrary SQL commands via the search parameter in (1) index.php and (2) search.php. NOTE: This issue might overlap CVE-2004-0663.2.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 1.33% — more likely to be exploited than 70% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-01-22 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| powerportal | powerportal |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | PowerPortal 1.1/1.3 - 'index.php' Cross-Site Scripting | 2006-01-17 |
| exploit-db | PowerPortal 1.1/1.3 - 'search.php' Cross-Site Scripting | 2006-01-17 |
References
- http://secunia.com/advisories/10172
- http://web.archive.org/web/20050303003128/http://powerportal.sourceforge.net/
- http://www.osvdb.org/27957
- http://www.osvdb.org/27958
- http://www.securityfocus.com/archive/1/422151/100/0/threaded
- http://www.securityfocus.com/bid/16279
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24196
- http://secunia.com/advisories/10172
- http://web.archive.org/web/20050303003128/http://powerportal.sourceforge.net/
- http://www.osvdb.org/27957
- http://www.osvdb.org/27958
- http://www.securityfocus.com/archive/1/422151/100/0/threaded
- http://www.securityfocus.com/bid/16279
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24196
→ the Explorer · watch your stack · NVD