CVE-2006-3292
Estado: ModificadaAlta (7.5)—
SQL injection vulnerability in the Search gadget in Jaws 0.6.2 allows remote attackers to execute arbitrary SQL commands via queries with the "LIKE" keyword in the searchdata parameter (search field).
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 4.67%
- Percentil entre todas las CVEs puntuadas: 92
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://retrogod.altervista.org/JAWS_062_sql.html
- http://secunia.com/advisories/20842
- http://securityreason.com/securityalert/1165
- http://www.jaws-project.com/index.php?blog/show/29
- http://www.securityfocus.com/archive/1/438434/100/0/threaded
- http://www.securityfocus.com/bid/18665
- http://www.vupen.com/english/advisories/2006/2546
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27334
- http://retrogod.altervista.org/JAWS_062_sql.html
- http://secunia.com/advisories/20842
- http://securityreason.com/securityalert/1165
- http://www.jaws-project.com/index.php?blog/show/29
- http://www.securityfocus.com/archive/1/438434/100/0/threaded
- http://www.securityfocus.com/bid/18665
- http://www.vupen.com/english/advisories/2006/2546
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27334
JSON original (NVD)
Mostrar
{
"id": "CVE-2006-3292",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2006-06-28T23:05:00.000",
"references": [
{
"url": "http://retrogod.altervista.org/JAWS_062_sql.html",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/20842",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/1165",
"source": "cve@mitre.org"
},
{
"url": "http://www.jaws-project.com/index.php?blog/show/29",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/438434/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/18665",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2006/2546",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27334",
"source": "cve@mitre.org"
},
{
"url": "http://retrogod.altervista.org/JAWS_062_sql.html",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/20842",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityreason.com/securityalert/1165",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.jaws-project.com/index.php?blog/show/29",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/438434/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/18665",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2006/2546",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27334",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "SQL injection vulnerability in the Search gadget in Jaws 0.6.2 allows remote attackers to execute arbitrary SQL commands via queries with the \"LIKE\" keyword in the searchdata parameter (search field)."
},
{
"lang": "es",
"value": "Vulnerabilidad de inyección SQL en Search gadget en Jaws 0.6.2, permite a atacantes remotos ejecutar comandos SQL de su elección a través del parámetro searchdata con la opción LIKE."
}
],
"lastModified": "2026-06-16T22:26:47.153",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:jaws:jaws:0.6.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6C6D4750-A567-47D2-A250-574A4FF558DD"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}