CVE-2006-3168
Summary
| CVE | CVE-2006-3168 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-06-23 00:02:00 UTC |
| Updated | 2018-10-18 16:46:00 UTC |
| Description | SQL injection vulnerability in CS-Forum before 0.82 allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) debut parameters in (a) read.php, and the (3) search and (4) debut parameters in (b) index.php. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Comscripts | Cs-forum | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| CS-Forum <= 0.81 Cross Site Scripting, SQL Injection, Full Path Disclosure - CXSecurity.com | SREASON | securityreason.com | |
| 26382 | OSVDB | www.osvdb.org | |
| www.comscripts.com/scripts/php.cs-forum.643.html | CONFIRM | www.comscripts.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| 26383 | OSVDB | www.osvdb.org | |
| new.fr is available for purchase - Sedo.com | MISC | www.acid-root.new.fr | Vendor Advisory |
| Secunia - Advisories - CS-Forum Multiple Vulnerabilities | SECUNIA | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.