CVE-2006-3559 Information

Description

Multiple SQL injection vulnerabilities in Arif Supriyanto auraCMS 1.62 allow remote attackers to execute arbitrary SQL commands and delete all shoutbox messages via the (1) name and (2) pesan parameters.

Reference

http://h1.ripway.com/lintah/adv/txt/01-iFX-2006-AuraCMS-v1.62-XSS-Bug.txt http://securityreason.com/securityalert/1226 http://www.osvdb.org/28201 http://www.securityfocus.com/archive/1/439494/100/0/threaded http://www.securityfocus.com/bid/18867 https://exchange.xforce.ibmcloud.com/vulnerabilities/27705

Share on: