CVE-2006-0147 is a dynamic code evaluation vulnerability in the ADOdb for PHP library, specifically within the tests/tmssql.php script. This flaw, present in various products including Mantis, Moodle, and PostNuke, allows remote attackers to execute arbitrary PHP functions by manipulating the 'do' parameter. With a CVSS score of 7.5, this vulnerability is considered highly severe, requiring no authentication and low attack complexity to achieve partial confidentiality, integrity, and availability impacts. While not listed in CISA's KEV catalog, exploit code for a related product (Simplog) exists on ExploitDB, indicating potential for active exploitation. Despite this, there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.66CPE matchmatch criteria | cpe:2.3:a:john_lim:adodb:4.66:*:*:*:*:*:*:* | ||
4.68CPE matchmatch criteria | cpe:2.3:a:john_lim:adodb:4.68:*:*:*:*:*:*:* | ||
0.19.4CPE matchmatch criteria | cpe:2.3:a:mantis:mantis:0.19.4:*:*:*:*:*:*:* | ||
1.0.0_rc4CPE matchmatch criteria | cpe:2.3:a:mantis:mantis:1.0.0_rc4:*:*:*:*:*:*:* | ||
1.5.3CPE matchmatch criteria | cpe:2.3:a:moodle:moodle:1.5.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.