CVE-2006-2499 Information
Feb 14, 2021
cve
Description
SQL injection vulnerability in default.asp in CodeAvalanche News (CANews) 1.2 allows remote attackers to execute arbitrary SQL commands via the password field.
Reference
http://colander.altervista.org/advisory/CANews.txt http://secunia.com/advisories/20171 http://www.osvdb.org/25652 http://www.securityfocus.com/archive/1/434730/100/0/threaded http://www.securityfocus.com/bid/18031 http://www.vupen.com/english/advisories/2006/1870 https://exchange.xforce.ibmcloud.com/vulnerabilities/26586
Share on: