CVE-2006-5840
Estado: AnalizadaAlta (7.5)—
Multiple SQL injection vulnerabilities in Abarcar Realty Portal allow remote attackers to execute arbitrary SQL commands via the (1) neid parameter to newsdetails.php, or the (2) slid parameter to slistl.php. NOTE: the cat vector is already covered by CVE-2006-2853. NOTE: the vendor has notified CVE that the current version only creates static pages, and that slistl.php/slid never existed in any version
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.08%
- Percentil entre todas las CVEs puntuadas: 81
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-89
Referencias
- http://attrition.org/pipermail/vim/2006-December/001190.html
- http://s-a-p.ca/index.php?page=OurAdvisories&id=7
- http://secunia.com/advisories/22792
- http://securityreason.com/securityalert/1840
- http://www.attrition.org/pipermail/vim/2006-December/001170.html
- http://www.osvdb.org/30249
- http://www.osvdb.org/30250
- http://www.securityfocus.com/archive/1/450946/100/0/threaded
- http://www.securityfocus.com/bid/20970
- http://www.vupen.com/english/advisories/2006/4418
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30135
- http://attrition.org/pipermail/vim/2006-December/001190.html
- http://s-a-p.ca/index.php?page=OurAdvisories&id=7
- http://secunia.com/advisories/22792
- http://securityreason.com/securityalert/1840
- http://www.attrition.org/pipermail/vim/2006-December/001170.html
- http://www.osvdb.org/30249
- http://www.osvdb.org/30250
- http://www.securityfocus.com/archive/1/450946/100/0/threaded
- http://www.securityfocus.com/bid/20970
- http://www.vupen.com/english/advisories/2006/4418
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30135
JSON original (NVD)
Mostrar
{
"id": "CVE-2006-5840",
"cveTags": [
{
"tags": [
"disputed"
],
"sourceIdentifier": "cve@mitre.org"
}
],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2006-11-10T02:07:00.000",
"references": [
{
"url": "http://attrition.org/pipermail/vim/2006-December/001190.html",
"tags": [
"Mailing List"
],
"source": "cve@mitre.org"
},
{
"url": "http://s-a-p.ca/index.php?page=OurAdvisories&id=7",
"tags": [
"URL Repurposed"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/22792",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/1840",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.attrition.org/pipermail/vim/2006-December/001170.html",
"tags": [
"Mailing List"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/30249",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/30250",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/450946/100/0/threaded",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/20970",
"tags": [
"Exploit",
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2006/4418",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/30135",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://attrition.org/pipermail/vim/2006-December/001190.html",
"tags": [
"Mailing List"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://s-a-p.ca/index.php?page=OurAdvisories&id=7",
"tags": [
"URL Repurposed"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/22792",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityreason.com/securityalert/1840",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.attrition.org/pipermail/vim/2006-December/001170.html",
"tags": [
"Mailing List"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/30249",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/30250",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/450946/100/0/threaded",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/20970",
"tags": [
"Exploit",
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2006/4418",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/30135",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple SQL injection vulnerabilities in Abarcar Realty Portal allow remote attackers to execute arbitrary SQL commands via the (1) neid parameter to newsdetails.php, or the (2) slid parameter to slistl.php. NOTE: the cat vector is already covered by CVE-2006-2853. NOTE: the vendor has notified CVE that the current version only creates static pages, and that slistl.php/slid never existed in any version"
},
{
"lang": "es",
"value": "** IMPUGNADA ** Múltiples vulnerabilidades de inyección SQL en \r\nAbarcar Realty Portal permiten a atacantes remotos ejecutar comandos SQL de su elección mediante (1) el parámetro neid en newsdetails.php, o (2) el parámetro slid en slistl.php.\r\nNOTA: el vector cat ya está tratado en CVE-2006-2853. NOTA: el fabricante ha notificado a CVE que la versión actual sólo crea páginas estáticas, y que slisl.php/slid nunca existió en ninguna versión."
}
],
"lastModified": "2026-06-16T22:31:58.920",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:abarcar:abarcar_realty_portal:5.1.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DE14B3E1-74AA-4E49-A010-B988564A113B"
},
{
"criteria": "cpe:2.3:a:abarcar:abarcar_realty_portal:6.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F11DEC59-C6B9-443D-B907-8ED9B03D3D41"
}
],
"operator": "OR"
}
]
}
],
"vendorComments": [
{
"comment": "The version 5.1.5 of the abarcar Realty Portal has been discontinued 2003.\nThe version 6.xx has been discontinued beginning 2006.\nA fix for above versions has been available since that time.\n\nAs of version 7.0 static pages are created\n- a parameter for cat.php is no longer used\n- the routine for news has been dropped and a different routine creating static pages is used\n- slistl.php never existed in the Realty Portal",
"lastModified": "2006-12-20T00:00:00",
"organization": "abarcar Software"
}
],
"sourceIdentifier": "cve@mitre.org"
}