Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2006-0610

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2006-0610
Last Modified 07 Mar 2011 09:30:26
Published 08 Feb 2006 07:02:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2006-0610

Summary

Multiple SQL injection vulnerabilities in 2200net Calendar system 1.2, with gpc_magic_quotes disabled, allow remote attackers to execute arbitrary SQL commands and bypass authentication via (1) the fm_data[id] parameter to calendar.php and (2) the $ad['acc'] variable in adminlogin.php.

Vulnerable Systems

Application

  • 2200net Calendar 1.2


References

XF - 2200net-adminlogin-sql-injection(24484)

XF - 2200net-calendar-sql-injection(24483)

VUPEN - ADV-2006-0486

MISC - http://www.evuln.com/vulns/62/summary.html

BID - 16569

BUGTRAQ - 20060215 [eVuln] 2200net Calendar system SQL Injection and Authentication Bypass Vulnerabilities

OSVDB - 23038

OSVDB - 23037

SECUNIA - 18781

BUGTRAQ - 20060215 [eVuln] 2200net Calendar system SQL Injection and Authentication


Last Updated: 27 May 2016 10:41:44