CVE-2006-3054 Information

Description

Multiple SQL injection vulnerabilities in VBZooM 1.11 allow remote attackers to execute arbitrary SQL commands via the (1) sobjectID or (2) MAINID parameters to (a) show.php or (3) MainID parameter to (b) subject.php.

Reference

http://www.securityfocus.com/archive/1/436938/100/0/threaded http://www.securityfocus.com/archive/1/436940/100/0/threaded http://www.securityfocus.com/bid/18403 https://exchange.xforce.ibmcloud.com/vulnerabilities/27070

Share on: