peter bassill · operator
$ cve CVE-2006-4444 JSON

CVE-2006-4444 EXPLOIT

6.5
MEDIUM · CVSS 2.0 · EPSS 3.1% (pctl 87)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in Cybozu Garoon 2.1.0 for Windows allow remote authenticated users to execute arbitrary SQL commands via the (1) tid parameter in the (a) todo/view (aka TODO List View), (b) todo/modify (aka TODO List Modify), or (c) todo/delete functionality; the (2) pid parameter in the (d) workflow/view or (e) workflow/print functionality; the (3) uid parameter in the (f) schedule/user_view, (g) phonemessage/add, (h) phonemessage/history, or (i) schedule/view functionality; the (4) cid parameter in (j) todo/index; the (5) iid parameter in the (k) memo/view or (l) memo/print functionality; or the (6) event parameter in the (m) schedule/view functionality.

Scoring

CVSS6.5 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS3.08% — more likely to be exploited than 87% of all CVEs
On CISA KEVno
Public exploityes
Published2006-08-29
Last modified2026-06-16

Affected (1)

VendorProduct
cybozugaroon

Public exploits

SourceTitleDate
exploit-dbCybuzu Garoon 2.1.0 - Multiple SQL Injections2006-08-28

References

→ the Explorer  ·  watch your stack  ·  NVD