Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2006-3092

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2006-3092
Last Modified 05 Sep 2008 05:06:13
Published 19 Jun 2006 05:02:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2006-3092

Summary

PhpMyFactures 1.2 and earlier allows remote attackers to bypass authentication and modify data via direct requests with modified parameters to (1) /tva/ajouter_tva.php, (2) /remises/ajouter_remise.php, (3) /pays/ajouter_pays.php, (4) /pays/modifier_pays.php, (5) /produits/ajouter_cat.php, (6) /produits/ajouter_produit.php, (7) /clients/ajouter_client.php, (8) /clients/modifier_client.php. NOTE: the provenance of this information is unknown; portions of the details are obtained from third party information.

Vulnerable Systems

Application

  • Phpmyfactures 1.0

  • Phpmyfactures 1.2


References

BUGTRAQ - 20060610 PhpMyFactures 1.0 Cross Site Scripting, SQL Injection, Full Path Disclosure and others

MISC - http://www.acid-root.new.fr/advisories/phpmyfactures.txt

SECUNIA - 20642

XF - phpmyfactures-multiple-data-manipulation(27206)

OSVDB - 26477

SREASON - 1111


Last Updated: 27 May 2016 10:42:52