CVE-2006-1278
Summary
| CVE | CVE-2006-1278 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-03-19 11:06:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | SQL injection vulnerability in @1 File Store 2006.03.07 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) functions.php and (2) user.php in the libs directory, (3) edit.php and (4) delete.php in control/files/, (5) edit.php and (6) delete.php in control/users/, (7) edit.php, (8) access.php, and (9) in control/folders/, (10) access.php and (11) delete.php in control/groups/, (12) confirm.php, and (13) download.php; (14) the email parameter in password.php, and (15) the id parameter in folder.php. NOTE: it was later reported that vectors 12 and 13 also affect @1 File Store PRO 3.2. |
Risk And Classification
Primary CVSS: v2.0 6.8 from [email protected]
AV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS: 0.026250000 probability, percentile 0.856950000 (date 2026-04-17)
Problem Types: CWE-89 | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Upoint | @1 File Store | 2006.03.07 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.osvdb.org/23852 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| eVuln.com - @1 File Store Multiple XSS and SQL Injection Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | evuln.com | Exploit |
| www.osvdb.org/23863 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| @1 File Store Multiple Input Validation Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| www.osvdb.org/23859 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| www.osvdb.org/23861 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| SecurityTracker.com Archives - [Vendor Has Issued a Fix] @1 File Store Input Validation Flaws Permit Cross-Site Scripting and SQL Injection Attacks | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Exploit |
| www.osvdb.org/23854 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| www.osvdb.org/23856 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| @1 File Store Script Insertion and SQL Injection - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| File Store PRO 'download.php' SQL Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| [VIM] @1 File Store PRO SQL injection - the old gray dupe | af854a3a-2127-422b-91ae-364da2661108 | www.attrition.org | |
| www.osvdb.org/23857 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| www.osvdb.org/23855 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| www.osvdb.org/23864 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| osvdb.org/47017 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| www.osvdb.org/23851 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | Exploit |
| www.osvdb.org/23860 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| SecurityReason | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | Exploit |
| osvdb.org/47018 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| @1 File Store PRO "id" SQL Injection Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| www.osvdb.org/24106 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| www.osvdb.org/23858 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| File Store PRO 3.2 Multiple Blind SQL Injection Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| www.osvdb.org/23862 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| www.osvdb.org/23853 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.