CVE-2006-3332
Summary
| CVE | CVE-2006-3332 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-06-30 23:05:00 UTC |
| Updated | 2017-07-20 01:32:00 UTC |
| Description | SQL injection vulnerability in index.php in Zorum Forum 3.5 allows remote attackers to execute arbitrary SQL commands via the (1) offset, (2) tid, (3) fromid, (4) sortby, (5) fromfrommethod, and (6) fromfromlist parameters. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Phpoutsourcing | Zorum | 3.0 | All | All | All |
| Application | Phpoutsourcing | Zorum | 3.1 | All | All | All |
| Application | Phpoutsourcing | Zorum | 3.2 | All | All | All |
| Application | Phpoutsourcing | Zorum | 3.3 | All | All | All |
| Application | Phpoutsourcing | Zorum | 3.4 | All | All | All |
| Application | Phpoutsourcing | Zorum | 3.5 | All | All | All |
| Application | Phpoutsourcing | Zorum | 3.0 | All | All | All |
| Application | Phpoutsourcing | Zorum | 3.1 | All | All | All |
| Application | Phpoutsourcing | Zorum | 3.2 | All | All | All |
| Application | Phpoutsourcing | Zorum | 3.3 | All | All | All |
| Application | Phpoutsourcing | Zorum | 3.4 | All | All | All |
| Application | Phpoutsourcing | Zorum | 3.5 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityTracker.com Archives - Zorum Input Validation Flaw in Several 'index.php' Parameters Lets Remote Users Inject SQL Commands | SECTRACK | securitytracker.com | |
| Zorum Multiple SQL Injection Vulnerabilities | BID | www.securityfocus.com | |
| - UNSECURED SYSTEMS -: Zorum Forum <=3.5 vuln. | MISC | pridels0.blogspot.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.