Multiple SQL injection vulnerabilities in ModernBill 4.3.2 and earlier allow remote attackers or administrators to execute arbitrary SQL commands via the (1) id parameter in (a) user.php, or (2) where and (3) order parameters to (b) admin.php.
References
Configurations
History
21 Nov 2024, 00:09
Type | Values Removed | Values Added |
---|---|---|
References | () http://pridels0.blogspot.com/2006/04/modernbill-multiple-sql-inj-vuln.html - | |
References | () http://secunia.com/advisories/19641 - | |
References | () http://www.securityfocus.com/bid/17596 - | |
References | () http://www.vupen.com/english/advisories/2006/1415 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/25926 - |
Information
Published : 2006-04-19 16:06
Updated : 2025-04-03 01:03
NVD link : CVE-2006-1853
Mitre link : CVE-2006-1853
CVE.ORG link : CVE-2006-1853
JSON object : View
Products Affected
moderngigabyte
- modernbill
CWE