CVE-2006-4347

SQL injection vulnerability in user logon authentication request handling in Cool_CoolD.exe in Cool Manager 5.0 (5,60,90,28) and Cool Messenger Office/School Server 5.5 (5,65,12,13) allows remote attackers to execute arbitrary SQL commands via the username field.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:jiran:cool_manager:5.0:*:*:*:*:*:*:*
cpe:2.3:a:jiran:cool_messenger_office_school_server:5.5:*:*:*:*:*:*:*

History

21 Nov 2024, 00:15

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/fulldisclosure/2006-08/0605.html - () http://archives.neohapsis.com/archives/fulldisclosure/2006-08/0605.html -
References () http://secunia.com/advisories/21569 - Patch, Vendor Advisory () http://secunia.com/advisories/21569 - Patch, Vendor Advisory
References () http://vuln.sg/coolmessenger55-en.html - Patch, Vendor Advisory () http://vuln.sg/coolmessenger55-en.html - Patch, Vendor Advisory
References () http://www.osvdb.org/28117 - () http://www.osvdb.org/28117 -
References () http://www.securityfocus.com/bid/19669 - () http://www.securityfocus.com/bid/19669 -
References () http://www.vupen.com/english/advisories/2006/3362 - () http://www.vupen.com/english/advisories/2006/3362 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/28531 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/28531 -

Information

Published : 2006-08-24 21:04

Updated : 2025-04-03 01:03


NVD link : CVE-2006-4347

Mitre link : CVE-2006-4347

CVE.ORG link : CVE-2006-4347


JSON object : View

Products Affected

jiran

  • cool_messenger_office_school_server
  • cool_manager