VULNERABILITY INTELLIGENCE

CVE-2006-2189

CVSS score10 HIGH
EPSS probability2.40%
CISA KEVNot currently listed
Published2006-05-04
Last modified2026-06-16
CVSS vectorAV:N/AC:L/Au:N/C:C/I:C/A:C

Description

SQL injection vulnerability in search.php in Servous sBLOG 0.7.2 allows remote attackers to execute arbitrary SQL commands via the keyword parameter. NOTE: this issue can be used to trigger path disclosure. In addition, it might be primary to vector 1 in CVE-2006-1135.

Primary references