CVE-2006-3515
Summary
| CVE | CVE-2006-3515 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-07-11 23:05:00 UTC |
| Updated | 2018-10-18 16:47:00 UTC |
| Description | SQL injection vulnerability in the loginADP function in ajaxp.php in AjaxPortal 3.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password parameters. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Myiosoft.com | Ajaxportal | 3.0 | All | All | All |
| Application | Myiosoft.com | Ajaxportal | 3.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| AjaxPortal LoginADP Function SQL Injection Vulnerability | BID | www.securityfocus.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| KAPDA :: AjaxPortal v.3.0Authentication Bypass | MISC | www.kapda.ir | Vendor Advisory |
| Secunia - Advisories - AjaxPortal SQL Injection Vulnerabilities | SECUNIA | secunia.com | |
| AjaxPortal Authentication Bypass - CXSecurity.com | SREASON | securityreason.com | |
| 27067 | OSVDB | www.osvdb.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.