CVE-2006-1817

SQL injection vulnerability in authcheck.php in warforge.NEWS 1.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the (1) authusername and possibly the (2) authpassword cookie.
Configurations

Configuration 1 (hide)

cpe:2.3:a:the_war_forge:warforge.news:1.0:*:*:*:*:*:*:*

History

21 Nov 2024, 00:09

Type Values Removed Values Added
References () http://evuln.com/vulns/125/summary.html - () http://evuln.com/vulns/125/summary.html -
References () http://www.securityfocus.com/archive/1/432104/100/0/threaded - () http://www.securityfocus.com/archive/1/432104/100/0/threaded -
References () http://www.securityfocus.com/bid/17520 - () http://www.securityfocus.com/bid/17520 -
References () http://www.securityfocus.com/bid/17705 - () http://www.securityfocus.com/bid/17705 -
References () http://www.vupen.com/english/advisories/2006/1359 - () http://www.vupen.com/english/advisories/2006/1359 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/25900 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/25900 -

Information

Published : 2006-04-18 10:02

Updated : 2024-11-21 00:09


NVD link : CVE-2006-1817

Mitre link : CVE-2006-1817

CVE.ORG link : CVE-2006-1817


JSON object : View

Products Affected

the_war_forge

  • warforge.news