CVE Database
/

CVE-2006-3727

Back to search

CVE-2006-3727

Published: Jul 19, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple SQL injection vulnerabilities in Eskolar CMS 0.9.0.0 allow remote attackers to execute arbitrary SQL commands via the (1) gr_1_id, (2) gr_2_id, (3) gr_3_id, and (4) doc_id parameters in (a) index.php; the (5) uid and (6) pwd parameters in (b) php/esa.php; and possibly other vectors related to files in php/lib/ including (c) del.php, (d) download_backup.php, (e) navig.php, (f) restore.php, (g) set_12.php, (h) set_14.php, and (i) upd_doc.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

2032
exploit
x_refsource_EXPLOIT-DB
27399
vdb-entry
x_refsource_OSVDB
19045
vdb-entry
x_refsource_BID
eskolar-index-sql-injection(27808)
vdb-entry
x_refsource_XF
21101
third-party-advisory
x_refsource_SECUNIA
ADV-2006-2869
vdb-entry
x_refsource_VUPEN
27396
vdb-entry
x_refsource_OSVDB
27392
vdb-entry
x_refsource_OSVDB
27395
vdb-entry
x_refsource_OSVDB
27393
vdb-entry
x_refsource_OSVDB
27397
vdb-entry
x_refsource_OSVDB
27391
vdb-entry
x_refsource_OSVDB
27398
vdb-entry
x_refsource_OSVDB
27394
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now