CVE-2006-6923

SQL injection vulnerability in newsletters/edition.php in bitweaver 1.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the tk parameter.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:bitweaver:bitweaver:1.1:*:*:*:*:*:*:*
cpe:2.3:a:bitweaver:bitweaver:1.1.1_beta:*:*:*:*:*:*:*
cpe:2.3:a:bitweaver:bitweaver:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:bitweaver:bitweaver:1.3.1:*:*:*:*:*:*:*

History

21 Nov 2024, 00:23

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/bugtraq/2006-11/0142.html - Exploit, Vendor Advisory () http://archives.neohapsis.com/archives/bugtraq/2006-11/0142.html - Exploit, Vendor Advisory
References () http://securityreason.com/securityalert/2144 - () http://securityreason.com/securityalert/2144 -
References () http://www.securityfocus.com/bid/20988 - Exploit, Vendor Advisory () http://www.securityfocus.com/bid/20988 - Exploit, Vendor Advisory
References () http://www.securityfocus.com/bid/20996 - Exploit, Vendor Advisory () http://www.securityfocus.com/bid/20996 - Exploit, Vendor Advisory
References () http://www.vupen.com/english/advisories/2006/4485 - () http://www.vupen.com/english/advisories/2006/4485 -

Information

Published : 2007-01-13 02:28

Updated : 2024-11-21 00:23


NVD link : CVE-2006-6923

Mitre link : CVE-2006-6923

CVE.ORG link : CVE-2006-6923


JSON object : View

Products Affected

bitweaver

  • bitweaver