peter bassill · operator
$ cve CVE-2006-4892 JSON

CVE-2006-4892 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.6% (pctl 85)

Patch early

A public exploit exists.

Description

SQL injection vulnerability in faqview.asp in Techno Dreams FAQ Manager Package 1.0 allows remote attackers to execute arbitrary SQL commands via the key parameter.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.6% — more likely to be exploited than 85% of all CVEs
On CISA KEVno
Public exploityes
Published2006-09-19
Last modified2026-06-16

Affected (1)

VendorProduct
techno dreamsfaq manager package

Public exploits

SourceTitleDate
exploit-dbTechno Dreams FAQ Manager 1.0 - SQL Injection2006-09-17

References

→ the Explorer  ·  watch your stack  ·  NVD