CVE-2006-3926
Summary
| CVE | CVE-2006-3926 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-07-31 21:04:00 UTC |
| Updated | 2017-07-20 01:32:00 UTC |
| Description | Multiple SQL injection vulnerabilities in PhpProBid 5.24 allow remote attackers to execute arbitrary SQL commands via the (1) view or (2) start parameters to (a) viewfeedback.php or the (3) orderType parameter to (b) categories.php. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Php Pro Bid | Php Pro Bid | 5.24 | All | All | All |
| Application | Php Pro Bid | Php Pro Bid | 5.24 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PHP Pro Bid Multiple Input Validation Vulnerabilities | BID | www.securityfocus.com | Exploit |
| 27546 | OSVDB | www.osvdb.org | |
| SecurityTracker.com Archives - PHP Pro Bid Input Validation Hole Permits Cross-Site Scripting Attacks and Input Validation Flaw Lets Remote Users Inject SQL Commands | SECTRACK | securitytracker.com | Exploit |
| SecurityReason - Phpprobid <= 5.24 XSS SQL injection Vulnerability | SREASON | securityreason.com | |
| 27545 | OSVDB | www.osvdb.org | |
| PHP Pro Bid Cross-Site Scripting and SQL Injection - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Neohapsis Archives - Bugtraq - #0474 - Phpprobid <= 5.24 XSS SQL injection Vulnerability | BUGTRAQ | archives.neohapsis.com | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.