CyberSec.Space Logo
Back to CVE Browser

CVE-2006-6270

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.1970%
EPSS Percentile0.83th
PublishedDec 4, 2006
Last ModifiedApr 23, 2026

Vulnerability Description

Multiple SQL injection vulnerabilities in ASPMForum allow remote attackers to execute arbitrary SQL commands via (1) the soruid parameter in forum2.asp, (2) the ak parameter in kullanicilistesi.asp, (3) the kelimeler parameter in aramayap.asp, and (4) the kullaniciadi parameter in giris.asp; and allow remote authenticated users to execute arbitrary SQL commands via (5) the mesajno parameter in mesajkutum.asp. NOTE: the harf parameter in kullanicilistesi.asp and the baslik parameter in forum.asp are already covered by CVE-2005-4141.

Affected Platforms (CPE)

πŸ“¦
Kervancilar

Aspmforum

All versions

References & Advisories

Related Vulnerabilities