Back
CVE-2006-0913
SQL injection vulnerability in whineatnews.pl in Bugzilla 2.17 through 2.18.4 and 2.20 allows remote authenticated users with administrative privileges to execute arbitrary SQL commands via the whinedays parameter, as accessible from editparams.cgi.
Published: Feb 28, 2006
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (22)
| Vendor | Product | Version |
|---|---|---|
| mozilla | bugzilla | 2.17.1 |
| mozilla | bugzilla | 2.17.3 |
| mozilla | bugzilla | 2.17.4 |
| mozilla | bugzilla | 2.17.5 |
| mozilla | bugzilla | 2.17.6 |
| mozilla | bugzilla | 2.17.7 |
| mozilla | bugzilla | 2.18 |
| mozilla | bugzilla | 2.18 |
| mozilla | bugzilla | 2.18 |
| mozilla | bugzilla | 2.18.1 |
| mozilla | bugzilla | 2.18.2 |
| mozilla | bugzilla | 2.18.3 |
| mozilla | bugzilla | 2.18.4 |
| mozilla | bugzilla | 2.19 |
| mozilla | bugzilla | 2.19.1 |
| mozilla | bugzilla | 2.19.2 |
| mozilla | bugzilla | 2.19.3 |
| mozilla | bugzilla | 2.20 |
| mozilla | bugzilla | 2.20 |
| mozilla | bugzilla | 2.20 |
…and 2 more
GitHub Security Advisory GHSA-46fm-qcpg-4p27
SQL injection vulnerability in whineatnews.pl in Bugzilla 2.17 through 2.18.4 and 2.20 allows...
References (14)
- http://secunia.com/advisories/18979 Vendor Advisory
- http://www.osvdb.org/23378
- http://www.securityfocus.com/archive/1/425584/100/0/threaded
- http://www.securityfocus.com/bid/16738 Vendor Advisory
- http://www.vupen.com/english/advisories/2006/0692
- https://bugzilla.mozilla.org/show_bug.cgi?id=312498 Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24819
- http://secunia.com/advisories/18979 Vendor Advisory
- http://www.osvdb.org/23378
- http://www.securityfocus.com/archive/1/425584/100/0/threaded
- http://www.securityfocus.com/bid/16738 Vendor Advisory
- http://www.vupen.com/english/advisories/2006/0692
- https://bugzilla.mozilla.org/show_bug.cgi?id=312498 Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24819
Risk Scores
CVSS Score
5.5 / 10
EPSS Score
1.04%
Top 39% most likely to be exploited
Threat Score
22.3 / 100
Data Sources
NVD
EPSS
GitHub