Vulnerability Details CVE-2006-2065
SQL injection vulnerability in save.php in PHPSurveyor 0.995 and earlier allows remote attackers to execute arbitrary SQL commands via the surveyid cookie. NOTE: this issue could be leveraged to execute arbitrary PHP code, as demonstrated by inserting directory traversal sequences into the database, which are then processed by the thissurvey['language'] variable.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.015
EPSS Ranking 80.3%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2006-2065
-
cpe:2.3:a:phpsurveyor:phpsurveyor:0.96_beta
-
cpe:2.3:a:phpsurveyor:phpsurveyor:0.97_beta
-
cpe:2.3:a:phpsurveyor:phpsurveyor:0.98_beta
-
cpe:2.3:a:phpsurveyor:phpsurveyor:0.98_stable
-
cpe:2.3:a:phpsurveyor:phpsurveyor:0.99
-
cpe:2.3:a:phpsurveyor:phpsurveyor:0.991
-
cpe:2.3:a:phpsurveyor:phpsurveyor:0.992
-
cpe:2.3:a:phpsurveyor:phpsurveyor:0.993
-
cpe:2.3:a:phpsurveyor:phpsurveyor:0.995