CVE Database
/

CVE-2006-3940

Back to search

CVE-2006-3940

Published: Jul 31, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple SQL injection vulnerabilities in phpbb-Auction allow remote attackers to execute arbitrary SQL commands via (1) the ar parameter in auction_room.php and (2) the u parameter in auction_store.php. NOTE: the auction_rating.php vector is already covered by CVE-2005-1234. NOTE: the original disclosure states that the product name is "PHP-Auction", but this is probably an error.

VendorProductVersions

n/a

n/a

affected
n/a

References

20060725 PHP-Auction SQL injection
mailing-list
x_refsource_BUGTRAQ
19179
vdb-entry
x_refsource_BID
1306
third-party-advisory
x_refsource_SREASON

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now