Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2006-3860


IBM Informix Dynamic Server (IDS) before 9.40.xC7 and 10.00 before 10.00.xC3 allows allows remote authenticated users to execute arbitrary commands via the (1) "SET DEBUG FILE" SQL command, and the (2) start_onpload and (3) dbexp functions.


Published

2006-08-17T01:04:00.000

Last Modified

2025-04-03T01:03:51.193

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ibm informix_dynamic_database_server 7.3 Yes
Application ibm informix_dynamic_database_server 7.31_.xd8 Yes
Application ibm informix_dynamic_database_server 9.4 Yes
Application ibm informix_dynamic_database_server 9.40.tc5 Yes
Application ibm informix_dynamic_database_server 9.40.uc1 Yes
Application ibm informix_dynamic_database_server 9.40.uc2 Yes
Application ibm informix_dynamic_database_server 9.40.uc3 Yes
Application ibm informix_dynamic_database_server 9.40.uc5 Yes
Application ibm informix_dynamic_database_server 9.40.xc7 Yes
Application ibm informix_dynamic_database_server 10.0 Yes
Application ibm informix_dynamic_database_server 10.0_xc3 Yes

References