peter bassill · operator
$ cve CVE-2006-0823 JSON

CVE-2006-0823 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 1.7% (pctl 76)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in Geeklog 1.4.0 before 1.4.0sr1 and 1.3.11 before 1.3.11sr4 allow remote attackers to inject arbitrary SQL commands via the (1) userid variable to users.php or (2) sessid variable to lib-sessions.php.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS1.67% — more likely to be exploited than 76% of all CVEs
On CISA KEVno
Public exploityes
Published2006-02-21
Last modified2026-06-16

Affected (1)

VendorProduct
geekloggeeklog

Public exploits

SourceTitleDate
exploit-dbGeeklog < 1.4.0 - Multiple Vulnerabilities2016-02-19

References

→ the Explorer  ·  watch your stack  ·  NVD