Back
CVE-2006-0108
SQL injection vulnerability in mcl_login.asp in Timecan CMS allows remote attackers to execute arbitrary SQL commands via the email parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Due to the unavailability of the original source, it cannot be determined if this is the same issue as identified by CVE-2006-0107.
Published: Jan 7, 2006
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| idea_development_id_oy | timecan_cms | * |
GitHub Security Advisory GHSA-j6jh-98rm-wpmg
SQL injection vulnerability in mcl_login.asp in Timecan CMS allows remote attackers to execute...
References (8)
- http://www.osvdb.org/22252 Exploit
- http://www.osvdb.org/22253 Exploit
- http://www.vupen.com/english/advisories/2006/0078
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24014
- http://www.osvdb.org/22252 Exploit
- http://www.osvdb.org/22253 Exploit
- http://www.vupen.com/english/advisories/2006/0078
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24014
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
1.33%
Top 32% most likely to be exploited
Threat Score
30.4 / 100
Data Sources
NVD
EPSS
GitHub