CVE-2006-3430
Summary
| CVE | CVE-2006-3430 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-07-07 00:05:00 UTC |
| Updated | 2018-10-18 16:47:00 UTC |
| Description | SQL injection vulnerability in checkprofile.asp in (1) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1 and (2) Novell ZENworks 6.2 SR1 and earlier, allows remote attackers to execute arbitrary SQL commands via the agentid parameter. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Lumension | Patchlink Update Server | 6.1 | All | All | All |
| Application | Lumension | Patchlink Update Server | 6.2.0.181 | All | All | All |
| Application | Lumension | Patchlink Update Server | 6.2.0.189 | All | All | All |
| Application | Lumension | Patchlink Update Server | 6.1 | All | All | All |
| Application | Lumension | Patchlink Update Server | 6.2.0.181 | All | All | All |
| Application | Lumension | Patchlink Update Server | 6.2.0.189 | All | All | All |
| Application | Novell | Zenworks | All | sr1 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PatchLink Update Bugs Let Remote Users Inject SQL Commands, Modify the Configuration, and Create or Overwrite Files - SecurityTracker | SECTRACK | securitytracker.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| CXSecurity - IDS | SREASON | securityreason.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| About Secunia Research | Flexera | SECUNIA | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| [Full-disclosure] Multiple Vulnerabilities in PatchLink Update Server 6 | FULLDISC | lists.grok.org.uk | |
| PatchLink Update Checkprofile.ASP SQL Injection Vulnerability | BID | www.securityfocus.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Secunia - Advisories - Novell ZENworks Patch Management Multiple Vulnerabilities | SECUNIA | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.