AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2006-3135

HIGH · CVSS 7.5 EPSS 1.86%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2006-07-13 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.5. It may be remotely exploitable. It involves a SQL injection risk.

CVE
CVE-2006-3135
Severity
HIGH
CVSS
7.5
EPSS
1.86%

Original NVD Description

Multiple SQL injection vulnerabilities in CMS Mundo 1.0 build 008, and possibly other versions, allow remote attackers to execute arbitrary SQL commands via the (1) news_id parameter in the (a) news module, (2) searchstring parameter in (b) the search module, (3) id parameter in (c) the webshop module, (4) username parameter in (d) index.php, and (5) Name, (6) Address, (7) Zip, (8) City, (9) Country, and (10) Email fields during (e) a user profile update.