Back

CVE-2006-0774

SQL injection vulnerability in deleteSession() in DB_eSession library 1.0.2 and earlier, as used in multiple products, allows remote attackers to execute arbitrary SQL commands via the $_sess_id_set variable, which is usually derived from PHPSESSID.

Published: Feb 19, 2006 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
lawrence_osiris db_esession *

GitHub Security Advisory GHSA-v453-9c8g-w373

SQL injection vulnerability in deleteSession() in DB_eSession library 1.0.2 and earlier, as used...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.87%

Top 22% most likely to be exploited

Threat Score 30.6 / 100

Data Sources

NVD EPSS GitHub