CVE-2006-3752
Summary
| CVE | CVE-2006-3752 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-07-21 14:03:00 UTC |
| Updated | 2018-10-17 21:29:00 UTC |
| Description | Multiple SQL injection vulnerabilities in class.php in Professional Home Page Tools Guestbook allow remote attackers to execute arbitrary SQL commands via the (1) hidemail, (2) name, (3) mail, (4) ip, or (5) text parameters. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Professional Home Page Tools | Professional Home Page Tools Guestbook | All | All | All | All |
| Application | Professional Home Page Tools | Professional Home Page Tools Guestbook | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Professional Home Page Tools Gastebuch Input Validation Hole in 'class.php' Permits SQL Injection Attacks - SecurityTracker | SECTRACK | securitytracker.com | |
| abenteuer-mittelerde.de | MISC | artemis.abenteuer-mittelerde.de | Exploit |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Professional Home Page Tools Guestbook SQL Injection - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| Professional Home Page Tools Guestbook Multiple SQL Injection Vulnerabilities | BID | www.securityfocus.com | |
| Professional PHP Tools Guestbook Multiple Vulnerabilities - CXSecurity.com | SREASON | securityreason.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.