CVE Database
/

CVE-2006-3135

Back to search

CVE-2006-3135

Published: Jul 13, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple SQL injection vulnerabilities in CMS Mundo 1.0 build 008, and possibly other versions, allow remote attackers to execute arbitrary SQL commands via the (1) news_id parameter in the (a) news module, (2) searchstring parameter in (b) the search module, (3) id parameter in (c) the webshop module, (4) username parameter in (d) index.php, and (5) Name, (6) Address, (7) Zip, (8) City, (9) Country, and (10) Email fields during (e) a user profile update.

VendorProductVersions

n/a

n/a

affected
n/a

References

20589
third-party-advisory
x_refsource_SECUNIA
27143
vdb-entry
x_refsource_OSVDB
1236
third-party-advisory
x_refsource_SREASON
27139
vdb-entry
x_refsource_OSVDB
27140
vdb-entry
x_refsource_OSVDB
27142
vdb-entry
x_refsource_OSVDB
ADV-2006-2783
vdb-entry
x_refsource_VUPEN
27141
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now