CVE Database
/

CVE-2006-1495

Back to search

CVE-2006-1495

Published: Mar 30, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

SQL injection vulnerability in general/sendpassword.php in (1) PHPCollab 2.4 and 2.5.rc3, and (2) NetOffice 2.5.3-pl1 and 2.6.0b2 allows remote attackers to execute arbitrary SQL commands via the loginForm parameter in the "forgotten password" option.

VendorProductVersions

n/a

n/a

affected
n/a

References

19449
third-party-advisory
x_refsource_SECUNIA
ADV-2006-1141
vdb-entry
x_refsource_VUPEN
17286
vdb-entry
x_refsource_BID
1617
exploit
x_refsource_EXPLOIT-DB
19452
third-party-advisory
x_refsource_SECUNIA
ADV-2006-1142
vdb-entry
x_refsource_VUPEN
24230
vdb-entry
x_refsource_OSVDB
GLSA-200812-20
vendor-advisory
x_refsource_GENTOO
24226
vdb-entry
x_refsource_OSVDB
17283
vdb-entry
x_refsource_BID
33258
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now