← All CVEs

CVE-2006-0146

high · 7.5

The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to execute arbitrary SQL commands via the sql parameter.

7.5
CVSS
13.2%
EPSS (exploit prob.)
96th
EPSS percentile
2006-01-09
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Weaknesses

CWE-89

Affected products

VendorProductAffected versions
john_limadodb4.66
john_limadodb4.68
mantismantis0.19.4
mantismantis1.0.0_rc4
mediabeezmediabeezall versions
moodlemoodle1.5.3
postnuke_software_foundationpostnuke0.761
the_cacti_groupcacti0.8.6g

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2006-0146