HIGH
SQL injection vulnerability in index.php in SWSoft Confixx 3.0.6, 3.0.8, and 3.1.2 allows remote attackers to execute arbitrary SQL commands via the SID parameter
Published Apr 13, 2006
7.5
HIGHCVSS 2.0
EPSS 1.75%
Description
SQL injection vulnerability in index.php in SWSoft Confixx 3.0.6, 3.0.8, and 3.1.2 allows remote attackers to execute arbitrary SQL commands via the SID parameter.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (9)
- http://download1.swsoft.com/Confixx/security_hotfix/release_notes.txt x_refsource_CONFIRM
- http://secunia.com/advisories/19611 third-party-advisoryx_refsource_SECUNIAExploitPatchVendor Advisory
- http://www.securityfocus.com/archive/1/430671/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/430890/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/431421/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/17476 vdb-entryx_refsource_BIDExploit
- http://www.vupen.com/english/advisories/2006/1331 vdb-entryx_refsource_VUPEN
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2006-1754 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25749 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://download1.swsoft.com/Confixx/security_hotfix/release_notes.txt | x_refsource_CONFIRM | |
| http://secunia.com/advisories/19611 | third-party-advisoryx_refsource_SECUNIAExploitPatchVendor Advisory | |
| http://www.securityfocus.com/archive/1/430671/100/0/threaded | mailing-listx_refsource_BUGTRAQ | |
| http://www.securityfocus.com/archive/1/430890/100/0/threaded | mailing-listx_refsource_BUGTRAQ | |
| http://www.securityfocus.com/archive/1/431421/100/0/threaded | mailing-listx_refsource_BUGTRAQ | |
| http://www.securityfocus.com/bid/17476 | vdb-entryx_refsource_BIDExploit | |
| http://www.vupen.com/english/advisories/2006/1331 | vdb-entryx_refsource_VUPEN | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2006-1754 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/25749 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 13, 2006
Updated Aug 7, 2024
Reserved Apr 12, 2006
Link CVE-2006-1754
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2006-1754 Assigner mitre
Published Apr 13, 2006
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2006-1754