peter bassill · operator
$ cve CVE-2006-1000 JSON

CVE-2006-1000 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 3.4% (pctl 88)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in Pentacle In-Out Board 3.0 and earlier allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) newsid parameter to newsdetailsview.asp and (2) password parameter to login.asp.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS3.39% — more likely to be exploited than 88% of all CVEs
On CISA KEVno
Public exploityes
Published2006-03-06
Last modified2026-06-16

Affected (1)

VendorProduct
g2softpentacle in-out board

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD