CVE-2006-3860
Summary
| CVE | CVE-2006-3860 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-08-17 01:04:00 UTC |
| Updated | 2018-10-17 21:32:00 UTC |
| Description | IBM Informix Dynamic Server (IDS) before 9.40.xC7 and 10.00 before 10.00.xC3 allows allows remote authenticated users to execute arbitrary commands via the (1) "SET DEBUG FILE" SQL command, and the (2) start_onpload and (3) dbexp functions. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Informix Dynamic Database Server | 10.0 | All | All | All |
| Application | Ibm | Informix Dynamic Database Server | 10.0_xc3 | All | All | All |
| Application | Ibm | Informix Dynamic Database Server | 7.3 | All | All | All |
| Application | Ibm | Informix Dynamic Database Server | 7.31_.xd8 | All | All | All |
| Application | Ibm | Informix Dynamic Database Server | 9.4 | All | All | All |
| Application | Ibm | Informix Dynamic Database Server | 9.40.tc5 | All | All | All |
| Application | Ibm | Informix Dynamic Database Server | 9.40.uc1 | All | All | All |
| Application | Ibm | Informix Dynamic Database Server | 9.40.uc2 | All | All | All |
| Application | Ibm | Informix Dynamic Database Server | 9.40.uc3 | All | All | All |
| Application | Ibm | Informix Dynamic Database Server | 9.40.uc5 | All | All | All |
| Application | Ibm | Informix Dynamic Database Server | 9.40.xc7 | All | All | All |
| Application | Ibm | Informix Dynamic Database Server | 10.0 | All | All | All |
| Application | Ibm | Informix Dynamic Database Server | 10.0_xc3 | All | All | All |
| Application | Ibm | Informix Dynamic Database Server | 7.3 | All | All | All |
| Application | Ibm | Informix Dynamic Database Server | 7.31_.xd8 | All | All | All |
| Application | Ibm | Informix Dynamic Database Server | 9.4 | All | All | All |
| Application | Ibm | Informix Dynamic Database Server | 9.40.tc5 | All | All | All |
| Application | Ibm | Informix Dynamic Database Server | 9.40.uc1 | All | All | All |
| Application | Ibm | Informix Dynamic Database Server | 9.40.uc2 | All | All | All |
| Application | Ibm | Informix Dynamic Database Server | 9.40.uc3 | All | All | All |
| Application | Ibm | Informix Dynamic Database Server | 9.40.uc5 | All | All | All |
| Application | Ibm | Informix Dynamic Database Server | 9.40.xc7 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityReason - Multiple Arbitrary Command Execution Vulnerabilities | SREASON | securityreason.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Informix Dynamic Server Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Webmail | OVH- OVH | VUPEN | www.vupen.com | |
| IBM Informix Dynamic Server Multiple Vulnerabilities | BID | www.securityfocus.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| 27686 | OSVDB | www.osvdb.org | |
| 404 Not Found | MISC | www.databasesecurity.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| IBM notice: The page you requested cannot be displayed | CONFIRM | www-1.ibm.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.