Back to search
CVE-2007-6342
Published: Dec 13, 2007
Modified: Aug 7, 2024
PUBLISHED
Description
SQL injection vulnerability in the David Castro AuthCAS module (AuthCAS.pm) 0.4 for the Apache HTTP Server allows remote attackers to execute arbitrary SQL commands via the SESSION_COOKIE_NAME (session ID) in a cookie.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20080323 Re: Potential SQL injection vulnerability in Apache::AuthCAS
mailing-list
x_refsource_BUGTRAQ
26762
vdb-entry
x_refsource_BID
http://search.cpan.org/src/DCASTRO/Apache-AuthCAS-0.5/Changes
x_refsource_CONFIRM
29492
third-party-advisory
x_refsource_SECUNIA
20071207 Potential SQL injection vulnerability in Apache::AuthCAS
mailing-list
x_refsource_BUGTRAQ
3439
third-party-advisory
x_refsource_SREASON
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now