CVE-2006-0146
Summary
| CVE | CVE-2006-0146 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-01-09 23:03:00 UTC |
| Updated | 2018-10-19 15:42:00 UTC |
| Description | The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to execute arbitrary SQL commands via the sql parameter. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | John Lim | Adodb | 4.66 | All | All | All |
| Application | John Lim | Adodb | 4.68 | All | All | All |
| Application | John Lim | Adodb | 4.66 | All | All | All |
| Application | John Lim | Adodb | 4.68 | All | All | All |
| Application | Mantis | Mantis | 0.19.4 | All | All | All |
| Application | Mantis | Mantis | 1.0.0_rc4 | All | All | All |
| Application | Mantis | Mantis | 0.19.4 | All | All | All |
| Application | Mantis | Mantis | 1.0.0_rc4 | All | All | All |
| Application | Mediabeez | Mediabeez | All | All | All | All |
| Application | Mediabeez | Mediabeez | All | All | All | All |
| Application | Moodle | Moodle | 1.5.3 | All | All | All |
| Application | Moodle | Moodle | 1.5.3 | All | All | All |
| Application | Postnuke Software Foundation | Postnuke | 0.761 | All | All | All |
| Application | Postnuke Software Foundation | Postnuke | 0.761 | All | All | All |
| Application | The Cacti Group | Cacti | 0.8.6g | All | All | All |
| Application | The Cacti Group | Cacti | 0.8.6g | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Secunia - Advisories - Moodle ADOdb Insecure Test Scripts Security Issues | SECUNIA | secunia.com | Vendor Advisory |
| AgileBill ADOdb server.php Insecure Test Script Security Issue - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| PHPOpenChat ADOdb Insecure Test Scripts Security Issues - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Debian update for cacti - Secunia Advisories - Vulnerability Intelligence - Secunia.com | SECUNIA | secunia.com | Patch, Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| Debian -- Security Information -- DSA-1029-1 libphp-adodb | DEBIAN | www.debian.org | Patch, Vendor Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| ADOdb Server.PHP SQL Injection Vulnerability | BID | www.securityfocus.com | Exploit, Patch |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| Arbitrary SQL code execution via adodb :: MAXdev :: MDPro, the most easy to use and feature rich GPL Content Management System. | CONFIRM | www.maxdev.com | |
| Debian update for moodle - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| SecurityReason - Cacti: Multiple vulnerabilities in included ADOdb | SREASON | securityreason.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Secunia - Advisories - Mantis ADOdb Insecure Test Scripts Security Issues | SECUNIA | secunia.com | Vendor Advisory |
| Vulnerability and Virus Information - Secunia | MISC | secunia.com | Exploit, Patch, Vendor Advisory |
| Debian -- Security Information -- DSA-1031-1 cacti | DEBIAN | www.debian.org | Patch, Vendor Advisory |
| Xaraya ADOdb Insecure Test Scripts Security Issues - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| LifeType ADOdb "server.php" Insecure Test Script Security Issue - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| Error 404 :( | MISC | retrogod.altervista.org | Exploit |
| Secunia - Advisories - Gentoo update for cacti | SECUNIA | secunia.com | Vendor Advisory |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| MAXdev MD-Pro ADOdb "server.php" Insecure Test Script Security Issue - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| 22290 | OSVDB | www.osvdb.org | Exploit, Patch |
| Debian update for libphp-adodb - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| Gentoo Linux Documentation -- Cacti: Multiple vulnerabilities in included ADOdb | GENTOO | www.gentoo.org | Patch, Vendor Advisory |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Cacti ADOdb "server.php" Insecure Test Script Security Issue - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| MediaBeez "server.php" SQL Execution Vulnerability - Secunia Advisories - Vulnerability Information - Secunia.com | SECUNIA | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| ADOdb Insecure Test Scripts Security Issues - Advisories - Secunia | SECUNIA | secunia.com | Exploit, Patch, Vendor Advisory |
| PostNuke ADOdb "server.php" Insecure Test Script Security Issue - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| Xaraya :: Xaraya 1.0.2 Security Release | CONFIRM | www.xaraya.com | Patch |
| Debian -- Security Information -- DSA-1030-1 moodle | DEBIAN | www.debian.org | Patch, Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.