CVE-2006-3249 Information

Description

LICENSE README.md cvefilelist cvelist nvdcve nvdpages.sh scripts test-CVE-2017-1882.markdown test-CVE-2017-18822.markdown tmpvendorlinks DISPUTED LICENSE README.md cvefilelist cvelist nvdcve nvdpages.sh scripts test-CVE-2017-1882.markdown test-CVE-2017-18822.markdown tmpvendorlinks SQL injection vulnerability in search.php in Phorum 5.1.14 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the vendor has disputed this report stating \If a non positive integer or non-integer is used for the page parameter for a search URL the search query will use a negative number for the LIMIT clause. This causes the query to break showing no results. It IS NOT however a sql injection error.\ While the original report is from a researcher with mixed accuracy as of 20060703 CVE does not have any additional information regarding this issue.

Reference

http://pridels0.blogspot.com/2006/06/phorum-sql-injection-vuln.html http://www.osvdb.org/27165 http://www.phorum.org/cgi-bin/trac.cgi/ticket/382preview http://www.phorum.org/phorum5/read.php?14114358 https://exchange.xforce.ibmcloud.com/vulnerabilities/27369

Share on: