SQL injection vulnerability in @1 File Store 2006.03.07 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) functions.php and (2) user.php in the libs directory, (3) edit.php and (4) delete.php in control/files/, (5) edit.php and (6) delete.php in control/users/, (7) edit.php, (8) access.php, and (9) in control/folders/, (10) access.php and (11) delete.php in control/groups/, (12) confirm.php, and (13) download.php; (14) the email parameter in password.php, and (15) the id parameter in folder.php
Published Mar 19, 2006
6.8
MEDIUMCVSS 2.0
EPSS 3.74%
Description
SQL injection vulnerability in @1 File Store 2006.03.07 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) functions.php and (2) user.php in the libs directory, (3) edit.php and (4) delete.php in control/files/, (5) edit.php and (6) delete.php in control/users/, (7) edit.php, (8) access.php, and (9) in control/folders/, (10) access.php and (11) delete.php in control/groups/, (12) confirm.php, and (13) download.php; (14) the email parameter in password.php, and (15) the id parameter in folder.php. NOTE: it was later reported that vectors 12 and 13 also affect @1 File Store PRO 3.2.
Affected products
No data.
- 2006.03.07
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (31)
- http://evuln.com/vulns/95/summary.html x_refsource_MISCExploit
- http://osvdb.org/47017 vdb-entryx_refsource_OSVDB
- http://osvdb.org/47018 vdb-entryx_refsource_OSVDB
- http://secunia.com/advisories/19224 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/31063 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://securityreason.com/securityalert/619 third-party-advisoryx_refsource_SREASONExploit
- http://securitytracker.com/id?1015826 vdb-entryx_refsource_SECTRACKExploit
- http://www.attrition.org/pipermail/vim/2009-August/002246.html mailing-listx_refsource_VIM
- http://www.osvdb.org/23851 vdb-entryx_refsource_OSVDBExploit
- http://www.osvdb.org/23852 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/23853 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/23854 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/23855 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/23856 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/23857 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/23858 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/23859 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/23860 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/23861 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/23862 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/23863 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/23864 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/24106 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/archive/1/428659/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/17090 vdb-entryx_refsource_BID
- http://www.securityfocus.com/bid/30182 vdb-entryx_refsource_BIDExploit
- http://www.vupen.com/english/advisories/2006/0943 vdb-entryx_refsource_VUPENVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25183 vdb-entryx_refsource_XF
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43718 vdb-entryx_refsource_XF
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43724 vdb-entryx_refsource_XF
- https://www.exploit-db.com/exploits/6040 exploitx_refsource_EXPLOIT-DB
Change history (0)
No recorded changes yet.