MEDIUM
SQL injection vulnerability in class2.php in e107 0.7.2 and earlier allows remote attackers to execute arbitrary SQL commands via a cookie as defined in $pref['cookie_name']
Published May 16, 2006
5.1
MEDIUMCVSS 2.0
EPSS 1.24%
Description
SQL injection vulnerability in class2.php in e107 0.7.2 and earlier allows remote attackers to execute arbitrary SQL commands via a cookie as defined in $pref['cookie_name'].
Affected products
No data.
OR
- 0.6_10
- 0.6_11
- 0.6_12
- 0.6_13
- 0.6_14
- 0.6_15
- 0.6_15a
- 0.7
- 0.7.1
- 0.7.2
- 0.545
- 0.554
- 0.555_beta
- 0.603
- 0.616
- 0.617
- 0.6171
- 0.6175
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- http://secunia.com/advisories/20089 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://securityreason.com/securityalert/905 third-party-advisoryx_refsource_SREASON
- http://www.osvdb.org/25521 vdb-entryx_refsource_OSVDBPatch
- http://www.securityfocus.com/archive/1/433938/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/17966 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2006/1802 vdb-entryx_refsource_VUPENVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26434 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://secunia.com/advisories/20089 | third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory | |
| http://securityreason.com/securityalert/905 | third-party-advisoryx_refsource_SREASON | |
| http://www.osvdb.org/25521 | vdb-entryx_refsource_OSVDBPatch | |
| http://www.securityfocus.com/archive/1/433938/100/0/threaded | mailing-listx_refsource_BUGTRAQ | |
| http://www.securityfocus.com/bid/17966 | vdb-entryx_refsource_BID | |
| http://www.vupen.com/english/advisories/2006/1802 | vdb-entryx_refsource_VUPENVendor Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/26434 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 16, 2006
Updated Aug 7, 2024
Reserved May 15, 2006
Link CVE-2006-2416
CISA Vulnrichment
Updated n/a