CVE-2006-1766

Multiple SQL injection vulnerabilities in Papoo 2.1.5, and 3 beta1 and earlier, allow remote attackers to execute arbitrary SQL commands via the (1) getlang and (2) reporeid parameter in (a) index.php, (3) menuid parameter in (b) plugin.php and (c) forumthread.php, and (4) msgid parameter in forumthread.php.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:papoo:papoo:*:*:*:*:*:*:*:*
cpe:2.3:a:papoo:papoo:2.1.2:*:*:*:*:*:*:*
cpe:2.3:a:papoo:papoo:2.1.4:*:*:*:*:*:*:*
cpe:2.3:a:papoo:papoo:2.1.5:*:*:*:*:*:*:*

History

21 Nov 2024, 00:09

Type Values Removed Values Added
References () http://pridels0.blogspot.com/2006/04/papoo-multiple-sql-vuln.html - () http://pridels0.blogspot.com/2006/04/papoo-multiple-sql-vuln.html -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/25728 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/25728 -

Information

Published : 2006-04-13 10:02

Updated : 2024-11-21 00:09


NVD link : CVE-2006-1766

Mitre link : CVE-2006-1766

CVE.ORG link : CVE-2006-1766


JSON object : View

Products Affected

papoo

  • papoo