CVE-2006-3054

Properties

Published:
15.06.2006
Updated:
22.10.2018
Patch available:
Severity:
High
CVSS vector:
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Product:
vbzoom: vbzoom

Vulnerability description

Multiple SQL injection vulnerabilities in VBZooM 1.11 allow remote attackers to execute arbitrary SQL commands via the (1) sobjectID or (2) MAINID parameters to (a) show.php or (3) MainID parameter to (b) subject.php.

References:

BUGTRAQ: http://www.securityfocus.com/archive/1/436938/100/0/threaded
BUGTRAQ: http://www.securityfocus.com/archive/1/436940/100/0/threaded
BID: http://www.securityfocus.com/bid/18403
XF: https://exchange.xforce.ibmcloud.com/vulnerabilities/27070