CVE-2006-2749

SQL injection vulnerability in search.php in Open Searchable Image Catalogue (OSIC) 0.7.0.1 and earlier allows remote attackers to inject arbitrary SQL commands via the (1) txtCustomField and (2) CustomFieldID array parameters.
Configurations

Configuration 1 (hide)

cpe:2.3:a:open_searchable_image_catalogue:open_searchable_image_catalogue:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:11

Type Values Removed Values Added
References () http://secunia.com/advisories/20341 - Vendor Advisory () http://secunia.com/advisories/20341 - Vendor Advisory
References () http://securityreason.com/securityalert/1014 - () http://securityreason.com/securityalert/1014 -
References () http://securitytracker.com/id?1016178 - () http://securitytracker.com/id?1016178 -
References () http://sourceforge.net/forum/forum.php?forum_id=576483 - () http://sourceforge.net/forum/forum.php?forum_id=576483 -
References () http://svn.sourceforge.net/viewcvs.cgi/osic-win/branches/osic_0-7/osic/search.php?view=markup&rev=477 - () http://svn.sourceforge.net/viewcvs.cgi/osic-win/branches/osic_0-7/osic/search.php?view=markup&rev=477 -
References () http://www.seclab.tuwien.ac.at/advisories/TUVSA-0605-001.txt - Vendor Advisory () http://www.seclab.tuwien.ac.at/advisories/TUVSA-0605-001.txt - Vendor Advisory
References () http://www.securityfocus.com/archive/1/435380/100/0/threaded - () http://www.securityfocus.com/archive/1/435380/100/0/threaded -
References () http://www.securityfocus.com/bid/18169 - () http://www.securityfocus.com/bid/18169 -

Information

Published : 2006-06-01 10:02

Updated : 2025-04-03 01:03


NVD link : CVE-2006-2749

Mitre link : CVE-2006-2749

CVE.ORG link : CVE-2006-2749


JSON object : View

Products Affected

open_searchable_image_catalogue

  • open_searchable_image_catalogue