peter bassill · operator
$ cve CVE-2006-6861 JSON

CVE-2006-6861 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 1.5% (pctl 73)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in Outfront Spooky Login 2.7 allow remote attackers to execute arbitrary SQL commands via (1) the UserUpdate parameter to login/register.asp or (2) unspecified parameters to includes/a_register.asp.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS1.46% — more likely to be exploited than 73% of all CVEs
On CISA KEVno
Public exploityes
Published2006-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
outfrontspooky login

Public exploits

SourceTitleDate
exploit-dbSpooky 2.7 - 'login/register.asp' SQL Injection2006-12-30

References

→ the Explorer  ·  watch your stack  ·  NVD