Back

CVE-2006-1018

SQL injection vulnerability in poems.php in DCI-Designs Dawaween 1.03 allows remote attackers to execute arbitrary SQL commands via the id parameter in a diwan view action.

Published: Mar 7, 2006 Modified: Jun 16, 2026
CWE-89

CVSS Metrics

Affected Products (1)

Vendor Product Version
dci-designs dawaween 1.03

GitHub Security Advisory GHSA-p45p-rjjx-xhw8

SQL injection vulnerability in poems.php in DCI-Designs Dawaween 1.03 allows remote attackers to...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.14%

Top 36% most likely to be exploited

Threat Score 30.3 / 100

Data Sources

NVD EPSS GitHub