VDB
CVE-2006-3918
CVE-2006-3918
PUBLISHED
CVSS 9.300000190734863 CRITICAL
## Description Une vulnérabilité a été découverte dans le serveur web http sous OpenBSD. Une personne mal intentionnée peut exploiter cette vulnérabilité via une requête HTTP spécialement construite afin de conduire une attaque par injection de code indirecte. ## Solution Se référer au correctif de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
EPSS 91.37% · 99.7th percentile
Risk Scores
CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS Score
91.37%
99.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| N/A | N/A |
Exploit Intelligence
- Black-box web application penetration test of BadStore e-commerce platform. Covers SQL injection, CVE-2006-3918, HTTP request manipulation, OSINT-driven spear phishing, and MITRE ATT&CK-mapped findings. (github-poc)
- Black-box web application penetration test of BadStore e-commerce platform. Covers SQL injection, CVE-2006-3918, HTTP request manipulation, OSINT-driven spear phishing, and MITRE ATT&CK-mapped findings. (github-poc)
- Black-box web application penetration test of BadStore e-commerce platform. Covers SQL injection, CVE-2006-3918, HTTP request manipulation, OSINT-driven spear phishing, and MITRE ATT&CK-mapped findings. (github-poc)
- Black-box web application penetration test of BadStore e-commerce platform. Covers SQL injection, CVE-2006-3918, HTTP request manipulation, OSINT-driven spear phishing, and MITRE ATT&CK-mapped findings. (github-poc)
- Black-box web application penetration test of BadStore e-commerce platform. Covers SQL injection, CVE-2006-3918, HTTP request manipulation, OSINT-driven spear phishing, and MITRE ATT&CK-mapped findings. (github-poc)
- RHSA-2006:0618 (circl)
- 21172 (circl)
- DSA-1167 (circl)
- 19661 (circl)
- 21744 (circl)
…and 53 more exploits
Timeline
- Jul 28, 2006 CVE Published
- Jun 12, 2011 PoC Published
- Feb 4, 2022 EPSS Score
- Dec 30, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Dec 17, 2024 EPSS Score
- Mar 17, 2025 EPSS Score
- Mar 30, 2025 EPSS Score
- Mar 31, 2025 EPSS Score
- Apr 3, 2025 CVE Updated
- Apr 12, 2025 EPSS Score
- May 1, 2025 EPSS Score