Multiple SQL injection vulnerabilities in main.php in Chipmailer 1.09 allow remote attackers to execute arbitrary SQL commands via multiple parameters, as demonstrated by (1) anfang, (2) name, (3) mail, (4) anrede, (5) vorname, (6) nachname, (7) gebtag, (8) gebmonat, and (9) gebjahr.
References
Configurations
History
21 Nov 2024, 00:12
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=bugtraq&m=115024576618386&w=2 - | |
References | () http://secunia.com/advisories/20643 - Vendor Advisory | |
References | () http://securitytracker.com/id?1016315 - | |
References | () http://www.securityfocus.com/bid/18463 - | |
References | () http://www.vupen.com/english/advisories/2006/2359 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/27158 - |
Information
Published : 2006-06-21 01:02
Updated : 2024-11-21 00:12
NVD link : CVE-2006-3111
Mitre link : CVE-2006-3111
CVE.ORG link : CVE-2006-3111
JSON object : View
Products Affected
chipmailer
- chipmailer
CWE