CVE-2006-0759 Information
Description
Multiple SQL injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the contactgroupid parameter in addressbook.update.php (2) the messageid parameter in addressbook.add.php (3) the folderid parameter in folders.update.php and possibly certain parameters in (4) calendar.event.php (5) index.php (6) pop.download.php (7) read.bounce.php (8) rules.block.php (9) language.php and (10) certain other scripts; and allow remote authenticated users to execute arbitrary SQL commands via (11) the folderid parameter in index.php and (12) possibly other parameters in certain other scripts because $_SERVER[‘PHP_SELF’] is improperly handled.
Reference
http://archives.neohapsis.com/archives/bugtraq/2006-02/0162.html http://forum.hivemail.com/showthread.php?p=26745 http://secunia.com/advisories/18807 http://securityreason.com/securityalert/422 http://www.gulftech.org/?node=research&article_id=00098-02102006 http://www.securityfocus.com/bid/16591 http://www.vupen.com/english/advisories/2006/0527 https://exchange.xforce.ibmcloud.com/vulnerabilities/24623
Share on: