« Volver al listado

CVE-2006-6201

Estado: ModificadaAlta (7.5)—

Heap-based buffer overflow in Borland idsql32.dll 5.1.0.4, as used by RevilloC MailServer; 5.2.0.2 as used by Borland Developer Studio 2006; and possibly other versions allows remote attackers to execute arbitrary code via a long SQL statement, related to use of the DbiQExec function.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (6)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2006-6201",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": true,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2006-12-01T01:28:00.000",
  "references": [
    {
      "url": "http://secunia.com/advisories/22570",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/secunia_research/2006-70/advisory/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/453003/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/21342",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/4763",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/30583",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/22570",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/secunia_research/2006-70/advisory/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/453003/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/21342",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/4763",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/30583",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Heap-based buffer overflow in Borland idsql32.dll 5.1.0.4, as used by RevilloC MailServer; 5.2.0.2 as used by Borland Developer Studio 2006; and possibly other versions allows remote attackers to execute arbitrary code via a long SQL statement, related to use of the DbiQExec function."
    },
    {
      "lang": "es",
      "value": "Desbordamiento del buffer basado en pilas en el Borland idsql32.dll 5.1.0.4, como el usado en el RevilloC MailServer, la 5.2.0.2 como el usado en el Developer Studio 2006 y posiblemente otras versiones, permite a atacantes remotos ejecutar código de su elección a través de la declaración de una sentencia larga en SQL relacionada con el uso de la función DbiQExec."
    }
  ],
  "lastModified": "2026-06-16T22:32:40.240",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:borland_software:c\\+\\+_builder:5.x:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0692F6EA-B824-4D86-B871-7067379C99D3"
            },
            {
              "criteria": "cpe:2.3:a:borland_software:c\\+\\+_builder:6.x:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6C974CA6-63EE-4846-B6DB-5E94DEC7AD5F"
            },
            {
              "criteria": "cpe:2.3:a:borland_software:c\\+\\+_builder:2006:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9C96CF3B-20E8-42FD-AAC7-79FBF1A38A88"
            },
            {
              "criteria": "cpe:2.3:a:borland_software:c_builder:2006:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "93A52E6C-B30A-4C23-A082-322DF54ED9A6"
            },
            {
              "criteria": "cpe:2.3:a:borland_software:delphi:5.x:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8E3962B9-A4A5-45DC-87B4-E2AE144FD7FF"
            },
            {
              "criteria": "cpe:2.3:a:borland_software:delphi:6.x:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8535C9C4-D6E6-4ACC-8111-E81A127D11FF"
            },
            {
              "criteria": "cpe:2.3:a:borland_software:delphi:7.x:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "85A0E169-1DE6-4CFD-B919-CA9AFB23DB2B"
            },
            {
              "criteria": "cpe:2.3:a:borland_software:delphi:2006:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "75C29691-B481-4EFB-B258-3367509497CF"
            },
            {
              "criteria": "cpe:2.3:a:borland_software:developer_studio:2006:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A14BD3FB-EE97-4828-B99F-AD00FA5F9062"
            },
            {
              "criteria": "cpe:2.3:a:borland_software:idsql32.dll:5.1.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C1A1594E-A2D6-455E-B235-0F6E10B45F86"
            },
            {
              "criteria": "cpe:2.3:a:borland_software:idsql32.dll:5.1.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A74869CE-C6A2-463A-BB8A-633C924C6E0B"
            },
            {
              "criteria": "cpe:2.3:a:revilloc:mailserver:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8C4A185C-42B1-4D3A-94FC-A30DC75209FB"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}