CVE-2006-6706

SQL injection vulnerability in Soumu Workflow for Groupmax 01-00 through 01-01, Soumu Workflow 02-00 through 03-03, and Koukyoumuke Soumu Workflow 01-00 through 01-01 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors in certain web pages.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:soumu:koukyoumuke_soumu_workflow:01-00:*:*:*:*:*:*:*
cpe:2.3:a:soumu:koukyoumuke_soumu_workflow:01-01:*:*:*:*:*:*:*
cpe:2.3:a:soumu:soumo_workflow:01_00:*:*:*:*:*:*:*
cpe:2.3:a:soumu:soumo_workflow:01_01:*:*:*:*:*:*:*
cpe:2.3:a:soumu:soumu_workflow:02-00:*:*:*:*:*:*:*
cpe:2.3:a:soumu:soumu_workflow:02-01:*:*:*:*:*:*:*
cpe:2.3:a:soumu:soumu_workflow:03-03:*:*:*:*:*:*:*

History

No history.

Information

Published : 2006-12-23 01:28

Updated : 2024-02-28 11:01


NVD link : CVE-2006-6706

Mitre link : CVE-2006-6706

CVE.ORG link : CVE-2006-6706


JSON object : View

Products Affected

soumu

  • soumo_workflow
  • soumu_workflow
  • koukyoumuke_soumu_workflow
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')