CVE-2006-3384 Information

Description

SQL injection vulnerability in divers.php in Vincent Leclercq News 5.2 allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) texte parameters.

Reference

http://secunia.com/advisories/20936 http://www.acid-root.new.fr/advisories/news52.txt http://www.securityfocus.com/archive/1/438859/100/0/threaded http://www.securityfocus.com/bid/18775 http://www.vupen.com/english/advisories/2006/2642 https://exchange.xforce.ibmcloud.com/vulnerabilities/27504

Share on: