CVE-2006-0823

Multiple SQL injection vulnerabilities in Geeklog 1.4.0 before 1.4.0sr1 and 1.3.11 before 1.3.11sr4 allow remote attackers to inject arbitrary SQL commands via the (1) userid variable to users.php or (2) sessid variable to lib-sessions.php.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:geeklog:geeklog:1.3.11:*:*:*:*:*:*:*
cpe:2.3:a:geeklog:geeklog:1.3.11_sr1:*:*:*:*:*:*:*
cpe:2.3:a:geeklog:geeklog:1.3.11_sr2:*:*:*:*:*:*:*
cpe:2.3:a:geeklog:geeklog:1.3.11_sr3:*:*:*:*:*:*:*
cpe:2.3:a:geeklog:geeklog:1.4.0:*:*:*:*:*:*:*

History

21 Nov 2024, 00:07

Type Values Removed Values Added
References () http://secunia.com/advisories/18920 - Patch, Vendor Advisory () http://secunia.com/advisories/18920 - Patch, Vendor Advisory
References () http://www.geeklog.net/article.php/geeklog-1.4.0sr1 - () http://www.geeklog.net/article.php/geeklog-1.4.0sr1 -
References () http://www.gulftech.org/?node=research&article_id=00102-02192006 - () http://www.gulftech.org/?node=research&article_id=00102-02192006 -
References () http://www.osvdb.org/23348 - () http://www.osvdb.org/23348 -
References () http://www.securityfocus.com/archive/1/425506/100/0/threaded - () http://www.securityfocus.com/archive/1/425506/100/0/threaded -
References () http://www.securityfocus.com/bid/16755 - () http://www.securityfocus.com/bid/16755 -
References () http://www.vupen.com/english/advisories/2006/0661 - () http://www.vupen.com/english/advisories/2006/0661 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/24775 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/24775 -

Information

Published : 2006-02-21 23:02

Updated : 2024-11-21 00:07


NVD link : CVE-2006-0823

Mitre link : CVE-2006-0823

CVE.ORG link : CVE-2006-0823


JSON object : View

Products Affected

geeklog

  • geeklog