CVE Database
/

CVE-2006-3090

Back to search

CVE-2006-3090

Published: Jun 19, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple SQL injection vulnerabilities in PhpMyFactures 1.0, and possibly 1.2 and earlier, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) id_pays parameter in (a) /pays/modifier_pays.php; (2) id_produit, (3) quantite, (4) prix_ht, and (5) date parameter in (b) /stocks/ajouter.php; (6) id_cat parameter in (c) /produits/modifier_cat.php; (7) id_client parameter in (d) /clients/modifier_client.php; (8) id_remise parameter in (e) /remises/index.php; (9) id_taux parameter in (f) /tva/index.php; (10) ref_produit, and (11) id_stock parameter in (g) /stocks/index.php; (12) id_pays parameter in (h) /pays/index.php; and (13) id_cat parameter in (i) /produits/index.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

26472
vdb-entry
x_refsource_OSVDB
26473
vdb-entry
x_refsource_OSVDB
26469
vdb-entry
x_refsource_OSVDB
26471
vdb-entry
x_refsource_OSVDB
26476
vdb-entry
x_refsource_OSVDB
26470
vdb-entry
x_refsource_OSVDB
26474
vdb-entry
x_refsource_OSVDB
26475
vdb-entry
x_refsource_OSVDB
26467
vdb-entry
x_refsource_OSVDB
20642
third-party-advisory
x_refsource_SECUNIA
1111
third-party-advisory
x_refsource_SREASON

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now