CVE Database
/

CVE-2006-1278

Back to search

CVE-2006-1278

Published: Mar 19, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

SQL injection vulnerability in @1 File Store 2006.03.07 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) functions.php and (2) user.php in the libs directory, (3) edit.php and (4) delete.php in control/files/, (5) edit.php and (6) delete.php in control/users/, (7) edit.php, (8) access.php, and (9) in control/folders/, (10) access.php and (11) delete.php in control/groups/, (12) confirm.php, and (13) download.php; (14) the email parameter in password.php, and (15) the id parameter in folder.php. NOTE: it was later reported that vectors 12 and 13 also affect @1 File Store PRO 3.2.

VendorProductVersions

n/a

n/a

affected
n/a

References

23855
vdb-entry
x_refsource_OSVDB
23857
vdb-entry
x_refsource_OSVDB
23864
vdb-entry
x_refsource_OSVDB
31063
third-party-advisory
x_refsource_SECUNIA
23863
vdb-entry
x_refsource_OSVDB
23852
vdb-entry
x_refsource_OSVDB
ADV-2006-0943
vdb-entry
x_refsource_VUPEN
23861
vdb-entry
x_refsource_OSVDB
19224
third-party-advisory
x_refsource_SECUNIA
23853
vdb-entry
x_refsource_OSVDB
23860
vdb-entry
x_refsource_OSVDB
23856
vdb-entry
x_refsource_OSVDB
1015826
vdb-entry
x_refsource_SECTRACK
47018
vdb-entry
x_refsource_OSVDB
23858
vdb-entry
x_refsource_OSVDB
23854
vdb-entry
x_refsource_OSVDB
47017
vdb-entry
x_refsource_OSVDB
17090
vdb-entry
x_refsource_BID
23851
vdb-entry
x_refsource_OSVDB
23862
vdb-entry
x_refsource_OSVDB
6040
exploit
x_refsource_EXPLOIT-DB
619
third-party-advisory
x_refsource_SREASON
24106
vdb-entry
x_refsource_OSVDB
30182
vdb-entry
x_refsource_BID
23859
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now