Multiple SQL injection vulnerabilities in PHP Newsfeed 20040723 allow remote attackers to execute arbitrary SQL commands via the (1) name parameter to (a) deltables.php, (2) select, (3) header, (4) url, (5) source, or (6) time parameters to (b) manualsubmit.php, (7) num parameter to (c) delete.php, or (8) tablename parameter to (d) searchnews.php.
References
Configurations
History
21 Nov 2024, 00:10
Type | Values Removed | Values Added |
---|---|---|
References | () http://evuln.com/vulns/129/summary.html - | |
References | () http://secunia.com/advisories/19904 - Vendor Advisory | |
References | () http://www.osvdb.org/25132 - | |
References | () http://www.osvdb.org/25133 - | |
References | () http://www.osvdb.org/25134 - | |
References | () http://www.osvdb.org/25135 - | |
References | () http://www.securityfocus.com/bid/17757 - | |
References | () http://www.vupen.com/english/advisories/2006/1574 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/26205 - |
Information
Published : 2006-05-02 10:02
Updated : 2025-04-03 01:03
NVD link : CVE-2006-2139
Mitre link : CVE-2006-2139
CVE.ORG link : CVE-2006-2139
JSON object : View
Products Affected
wilsonncareabusinesses
- php_newsfeed
CWE