CVE Database
/

CVE-2006-2062

Back to search

CVE-2006-2062

Published: Apr 26, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple SQL injection vulnerabilities in Leadhound Full and LITE 2.1, and probably the Network Version "Full Version", allow remote attackers to execute arbitrary SQL commands via the (1) banner parameter in agent_links.pl; the offset parameter in (2) agent_links.pl, (3) agent_transactions.pl, (4) agent_subaffiliates.pl, and (5) agent_summary.pl; the camp_id parameter in (6) agent_transactions_csv.pl, (7) agent_subaffiliates.pl, and (8) agent_camp_det.pl; the (9) login parameter in agent_commission_statement.pl; the logged parameter in (10) agent_commission_statement.pl and (11) agent_camp_det.pl; the (12) agent_id parameter in agent_commission_statement.pl; and the (13) sub parameter in unspecified files.

VendorProductVersions

n/a

n/a

affected
n/a

References

25028
vdb-entry
x_refsource_OSVDB
25027
vdb-entry
x_refsource_OSVDB
25025
vdb-entry
x_refsource_OSVDB
19867
third-party-advisory
x_refsource_SECUNIA
25029
vdb-entry
x_refsource_OSVDB
25023
vdb-entry
x_refsource_OSVDB
25026
vdb-entry
x_refsource_OSVDB
25024
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now