{"api_version":"1","generated_at":"2026-07-23T11:12:32+00:00","cve":"CVE-2006-6387","urls":{"html":"https://cve.report/CVE-2006-6387","api":"https://cve.report/api/cve/CVE-2006-6387.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-6387","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-6387"},"summary":{"title":"CVE-2006-6387","description":"Multiple SQL injection vulnerabilities in LINK Content Management Server (CMS) allow remote attackers to execute arbitrary SQL commands via the (1) IDMeniGlavni parameter to navigacija.php, and the (2) IDStranicaPodaci parameter to prikazInformacije.php.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-12-08 01:28:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://secunia.com/advisories/23107","name":"http://secunia.com/advisories/23107","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Link CMS Cross-Site Scripting and SQL Injection - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/21464","name":"http://www.securityfocus.com/bid/21464","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Link CMS Multiple Input Validation Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30744","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30744","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-6387","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-6387","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"6387","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"link_content_management_server","cpe5":"link_content_management_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T20:26:46.034Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"21464","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/21464"},{"name":"23107","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23107"},{"name":"linkcms-prikazInformacije-sql-injection(30744)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30744"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-12-06T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple SQL injection vulnerabilities in LINK Content Management Server (CMS) allow remote attackers to execute arbitrary SQL commands via the (1) IDMeniGlavni parameter to navigacija.php, and the (2) IDStranicaPodaci parameter to prikazInformacije.php.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"21464","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/21464"},{"name":"23107","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23107"},{"name":"linkcms-prikazInformacije-sql-injection(30744)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30744"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-6387","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple SQL injection vulnerabilities in LINK Content Management Server (CMS) allow remote attackers to execute arbitrary SQL commands via the (1) IDMeniGlavni parameter to navigacija.php, and the (2) IDStranicaPodaci parameter to prikazInformacije.php.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"21464","refsource":"BID","url":"http://www.securityfocus.com/bid/21464"},{"name":"23107","refsource":"SECUNIA","url":"http://secunia.com/advisories/23107"},{"name":"linkcms-prikazInformacije-sql-injection(30744)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30744"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-6387","datePublished":"2006-12-08T01:00:00.000Z","dateReserved":"2006-12-07T00:00:00.000Z","dateUpdated":"2024-08-07T20:26:46.034Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-12-08 01:28:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:link_content_management_server:link_content_management_server:*:*:*:*:*:*:*:*","matchCriteriaId":"9D3C0660-5557-4C00-829D-1DB35963D0FA"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"6387","Ordinal":"1","Title":"CVE-2006-6387","CVE":"CVE-2006-6387","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"6387","Ordinal":"1","NoteData":"Multiple SQL injection vulnerabilities in LINK Content Management Server (CMS) allow remote attackers to execute arbitrary SQL commands via the (1) IDMeniGlavni parameter to navigacija.php, and the (2) IDStranicaPodaci parameter to prikazInformacije.php.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.","Type":"Description","Title":"CVE-2006-6387"},{"CveYear":"2006","CveId":"6387","Ordinal":"2","NoteData":"2006-12-07","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"6387","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}