Multiple SQL injection vulnerabilities in Papoo 2.1.5, and 3 beta1 and earlier, allow remote attackers to execute arbitrary SQL commands via the (1) getlang and (2) reporeid parameter in (a) index.php, (3) menuid parameter in (b) plugin.php and (c) forumthread.php, and (4) msgid parameter in forumthread.php.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:09
Type | Values Removed | Values Added |
---|---|---|
References | () http://pridels0.blogspot.com/2006/04/papoo-multiple-sql-vuln.html - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/25728 - |
Information
Published : 2006-04-13 10:02
Updated : 2024-11-21 00:09
NVD link : CVE-2006-1766
Mitre link : CVE-2006-1766
CVE.ORG link : CVE-2006-1766
JSON object : View
Products Affected
papoo
- papoo
CWE