HIGH
Multiple SQL injection vulnerabilities in Hosting Controller 6.1 before Hotfix 3.3 allow remote attackers to execute arbitrary SQL commands via the ForumID parameter in (1) DisableForum.asp and (2) enableForum.asp
Published Oct 31, 2006
7.5
HIGHCVSS 2.0
EPSS 3.22%
Description
Multiple SQL injection vulnerabilities in Hosting Controller 6.1 before Hotfix 3.3 allow remote attackers to execute arbitrary SQL commands via the ForumID parameter in (1) DisableForum.asp and (2) enableForum.asp. NOTE: it was later reported that the vulnerability is present in 6.1 Hotfix 3.3 and earlier.
Affected products
No data.
OR
- ≤ 6.1_hotfix_3.2
- 1.1
- 1.3
- 1.4
- 1.4.1
- 1.4b
- 6.1
- 6.1_hotfix_1.4
- 6.1_hotfix_1.7
- 6.1_hotfix_1.9
- 6.1_hotfix_2.0
- 6.1_hotfix_2.1
- 6.1_hotfix_2.2
- 6.1_hotfix_2.3
- 6.1_hotfix_2.4
- 6.1_hotfix_3.1
- 2002
- 2002_rc_1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (11)
- http://hostingcontroller.com/english/logs/Post-Hotfix-3_3-sec-Patch-ReleaseNotes.html x_refsource_CONFIRM
- http://secunia.com/advisories/22607 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/28973 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://securitytracker.com/id?1017103 vdb-entryx_refsource_SECTRACKExploitPatch
- http://www.kapda.ir/advisory-442.html x_refsource_MISCExploitPatchVendor Advisory
- http://www.securityfocus.com/archive/1/485028/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/20661 vdb-entryx_refsource_BIDExploitPatch
- http://www.securityfocus.com/bid/26862 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2006/4296 vdb-entryx_refsource_VUPENVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39036 vdb-entryx_refsource_XF
- https://www.exploit-db.com/exploits/4730 exploitx_refsource_EXPLOIT-DB
| Link | Providers | Tags |
|---|---|---|
| http://hostingcontroller.com/english/logs/Post-Hotfix-3_3-sec-Patch-ReleaseNotes.html | x_refsource_CONFIRM | |
| http://secunia.com/advisories/22607 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://secunia.com/advisories/28973 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://securitytracker.com/id?1017103 | vdb-entryx_refsource_SECTRACKExploitPatch | |
| http://www.kapda.ir/advisory-442.html | x_refsource_MISCExploitPatchVendor Advisory | |
| http://www.securityfocus.com/archive/1/485028/100/0/threaded | mailing-listx_refsource_BUGTRAQ | |
| http://www.securityfocus.com/bid/20661 | vdb-entryx_refsource_BIDExploitPatch | |
| http://www.securityfocus.com/bid/26862 | vdb-entryx_refsource_BID | |
| http://www.vupen.com/english/advisories/2006/4296 | vdb-entryx_refsource_VUPENVendor Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/39036 | vdb-entryx_refsource_XF | |
| https://www.exploit-db.com/exploits/4730 | exploitx_refsource_EXPLOIT-DB |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 31, 2006
Updated Aug 7, 2024
Reserved Oct 31, 2006
Link CVE-2006-5629
CISA Vulnrichment
Updated n/a