{"api_version":"1","generated_at":"2026-07-23T10:00:36+00:00","cve":"CVE-2006-3515","urls":{"html":"https://cve.report/CVE-2006-3515","api":"https://cve.report/api/cve/CVE-2006-3515.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-3515","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-3515"},"summary":{"title":"CVE-2006-3515","description":"SQL injection vulnerability in the loginADP function in ajaxp.php in AjaxPortal 3.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password parameters.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2006-07-11 23:05:00","updated_at":"2018-10-18 16:47:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"http://www.vupen.com/english/advisories/2006/2714","name":"ADV-2006-2714","refsource":"VUPEN","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/439614/100/0/threaded","name":"20060709 Re: [KAPDA::#46] - AjaxPortal Authentication Bypass","refsource":"BUGTRAQ","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/18897","name":"18897","refsource":"BID","tags":[],"title":"AjaxPortal LoginADP Function SQL Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securityfocus.com/archive/1/439521/100/0/threaded","name":"20060708 [KAPDA::#46] - AjaxPortal Authentication Bypass","refsource":"BUGTRAQ","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kapda.ir/advisory-355.html","name":"http://www.kapda.ir/advisory-355.html","refsource":"MISC","tags":["Vendor Advisory"],"title":"KAPDA :: AjaxPortal v.3.0Authentication Bypass","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://secunia.com/advisories/20985","name":"20985","refsource":"SECUNIA","tags":[],"title":"Secunia - Advisories - AjaxPortal SQL Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/1206","name":"1206","refsource":"SREASON","tags":[],"title":"AjaxPortal Authentication Bypass - CXSecurity.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/27067","name":"27067","refsource":"OSVDB","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-3515","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-3515","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"3515","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"myiosoft.com","cpe5":"ajaxportal","cpe6":"3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"3515","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"myiosoft.com","cpe5":"ajaxportal","cpe6":"3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-3515","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"SQL injection vulnerability in the loginADP function in ajaxp.php in AjaxPortal 3.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password parameters."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20060708 [KAPDA::#46] - AjaxPortal Authentication Bypass","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/439521/100/0/threaded"},{"name":"27067","refsource":"OSVDB","url":"http://www.osvdb.org/27067"},{"name":"20060709 Re: [KAPDA::#46] - AjaxPortal Authentication Bypass","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/439614/100/0/threaded"},{"name":"20985","refsource":"SECUNIA","url":"http://secunia.com/advisories/20985"},{"name":"18897","refsource":"BID","url":"http://www.securityfocus.com/bid/18897"},{"name":"http://www.kapda.ir/advisory-355.html","refsource":"MISC","url":"http://www.kapda.ir/advisory-355.html"},{"name":"ADV-2006-2714","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/2714"},{"name":"1206","refsource":"SREASON","url":"http://securityreason.com/securityalert/1206"}]}},"nvd":{"publishedDate":"2006-07-11 23:05:00","lastModifiedDate":"2018-10-18 16:47:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:myiosoft.com:ajaxportal:3.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"3515","Ordinal":"18840","Title":"CVE-2006-3515","CVE":"CVE-2006-3515","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"3515","Ordinal":"1","NoteData":"SQL injection vulnerability in the loginADP function in ajaxp.php in AjaxPortal 3.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password parameters.","Type":"Description","Title":null},{"CveYear":"2006","CveId":"3515","Ordinal":"2","NoteData":"2006-07-11","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"3515","Ordinal":"3","NoteData":"2018-10-18","Type":"Other","Title":"Modified"}]}}}