{"api_version":"1","generated_at":"2026-07-23T13:13:17+00:00","cve":"CVE-2006-3244","urls":{"html":"https://cve.report/CVE-2006-3244","api":"https://cve.report/api/cve/CVE-2006-3244.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-3244","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-3244"},"summary":{"title":"CVE-2006-3244","description":"Multiple SQL injection vulnerabilities in Anthill 0.2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) order parameter in buglist.php and the (2) bug parameter in query.php.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2006-06-27 10:05:00","updated_at":"2017-07-20 01:32:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"http://pridels0.blogspot.com/2006/06/anthill-sql-injection-vuln.html","name":"http://pridels0.blogspot.com/2006/06/anthill-sql-injection-vuln.html","refsource":"MISC","tags":[],"title":"- UNSECURED SYSTEMS -: Anthill SQL injection vuln.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/20838","name":"20838","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"Anthill SQL Injection Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/27373","name":"anthill-buglist-query-sql-injection(27373)","refsource":"XF","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/2529","name":"ADV-2006-2529","refsource":"VUPEN","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/18661","name":"18661","refsource":"BID","tags":[],"title":"Anthill Multiple SQL Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-3244","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-3244","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"3244","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"anthill","cpe5":"anthill","cpe6":"0.3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"3244","vulnerable":"1","versionEndIncluding":"0.2.6","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"anthill","cpe5":"anthill","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"3244","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"anthill","cpe5":"anthill","cpe6":"0.3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-3244","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple SQL injection vulnerabilities in Anthill 0.2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) order parameter in buglist.php and the (2) bug parameter in query.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"anthill-buglist-query-sql-injection(27373)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/27373"},{"name":"ADV-2006-2529","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/2529"},{"name":"18661","refsource":"BID","url":"http://www.securityfocus.com/bid/18661"},{"name":"20838","refsource":"SECUNIA","url":"http://secunia.com/advisories/20838"},{"name":"http://pridels0.blogspot.com/2006/06/anthill-sql-injection-vuln.html","refsource":"MISC","url":"http://pridels0.blogspot.com/2006/06/anthill-sql-injection-vuln.html"}]}},"nvd":{"publishedDate":"2006-06-27 10:05:00","lastModifiedDate":"2017-07-20 01:32:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":5.1},"severity":"MEDIUM","exploitabilityScore":4.9,"impactScore":6.4,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:anthill:anthill:*:*:*:*:*:*:*:*","versionEndIncluding":"0.2.6","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:anthill:anthill:0.3.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"3244","Ordinal":"18569","Title":"CVE-2006-3244","CVE":"CVE-2006-3244","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"3244","Ordinal":"1","NoteData":"Multiple SQL injection vulnerabilities in Anthill 0.2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) order parameter in buglist.php and the (2) bug parameter in query.php.","Type":"Description","Title":null},{"CveYear":"2006","CveId":"3244","Ordinal":"2","NoteData":"2006-06-27","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"3244","Ordinal":"3","NoteData":"2017-07-19","Type":"Other","Title":"Modified"}]}}}