Multiple SQL injection vulnerabilities in the login_user function in yans.func.php in Lucas Rodriguez San Pedro Yet Another News System (YANS) 0.2b allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:21
Type | Values Removed | Values Added |
---|---|---|
References | () http://archives.neohapsis.com/archives/bugtraq/2006-11/0121.html - Exploit | |
References | () http://securityreason.com/securityalert/1866 - | |
References | () http://www.securityfocus.com/bid/20963 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/30119 - |
Information
Published : 2006-11-15 15:07
Updated : 2024-11-21 00:21
NVD link : CVE-2006-5908
Mitre link : CVE-2006-5908
CVE.ORG link : CVE-2006-5908
JSON object : View
Products Affected
lucas_rodriguez_san_pedro
- yet_another_news_system
CWE