{ "canonical_id": "moodle--CVE-2006-0146", "system_id": "moodle", "display_name": "Moodle", "category": "cms", "advisory_mode": "core", "title": "CVE-2006-0146", "summary": "The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to execute arbitrary SQL commands via the sql parameter.", "published_at": "2006-01-09T23:03:00.000", "updated_at": "2025-04-03T01:03:51.193", "severity": "high", "cvss_score": 7.5, "exploit_status": "unknown", "source_confidence": "official", "official_source_url": "http://retrogod.altervista.org/phpopenchat_30x_sql_xpl.html", "secondary_source_urls": [ "http://secunia.com/advisories/17418", "http://secunia.com/advisories/18233", "http://secunia.com/advisories/18254", "http://secunia.com/advisories/18260", "http://secunia.com/advisories/18267", "http://secunia.com/advisories/18276", "http://secunia.com/advisories/18720", "http://secunia.com/advisories/19555", "http://secunia.com/advisories/19563", "http://secunia.com/advisories/19590", "http://secunia.com/advisories/19591", "http://secunia.com/advisories/19600", "http://secunia.com/advisories/19691", "http://secunia.com/advisories/19699", "http://secunia.com/advisories/24954", "http://secunia.com/secunia_research/2005-64/advisory/", "http://securityreason.com/securityalert/713", "http://www.debian.org/security/2006/dsa-1029", "http://www.debian.org/security/2006/dsa-1030", "http://www.debian.org/security/2006/dsa-1031", "http://www.gentoo.org/security/en/glsa/glsa-200604-07.xml", "http://www.maxdev.com/Article550.phtml", "http://www.osvdb.org/22290", "http://www.securityfocus.com/archive/1/423784/100/0/threaded", "http://www.securityfocus.com/archive/1/430448/100/0/threaded", "http://www.securityfocus.com/archive/1/466171/100/0/threaded", "http://www.securityfocus.com/bid/16187", "http://www.vupen.com/english/advisories/2006/0101", "http://www.vupen.com/english/advisories/2006/0102", "http://www.vupen.com/english/advisories/2006/0103", "http://www.vupen.com/english/advisories/2006/0104", "http://www.vupen.com/english/advisories/2006/0105", "http://www.vupen.com/english/advisories/2006/0370", "http://www.vupen.com/english/advisories/2006/0447", "http://www.vupen.com/english/advisories/2006/1304", "http://www.vupen.com/english/advisories/2006/1305", "http://www.vupen.com/english/advisories/2006/1419", "http://www.xaraya.com/index.php/news/569", "https://exchange.xforce.ibmcloud.com/vulnerabilities/24051" ], "aliases": [ "CVE-2006-0146" ], "cve_ids": [ "CVE-2006-0146" ], "ghsa_ids": [], "osv_ids": [], "affected_versions": [], "fixed_versions": [], "package_name": null, "render_markdown": false, "case_path": null, "secure_code_topics": [ "authz-server-side-recheck", "xss-output-encoding", "file-upload-validation" ], "status": "triage", "triage_reasons": [ "missing affected/fixed version details" ], "verification_status": "triage-manual", "verification_mode": "synthetic", "last_verified_at": null, "last_run_id": null, "evidence_bundle": null, "historical_status": null, "latest_status": null, "browser_evidence": { "required": false, "present": false, "refs": [] }, "repro_profile_id": "xss-generic", "artifact_mode": "synthetic", "blocked_reason": null, "metadata": { "source_names": [ "NVD Moodle" ], "source_kinds": [ "nvd-search" ], "candidate_count": 1 } }