CVE-2006-6754 Information

Description

Multiple SQL injection vulnerabilities in Ixprim 1.2 allow remote attackers to execute arbitrary SQL commands via the story_id parameter to ixm_ixpnews.php and unspecified other vectors.

Reference

http://acid-root.new.fr/poc/16061221.txt http://secunia.com/advisories/23453 http://securityreason.com/securityalert/2073 http://www.securityfocus.com/archive/1/455084/100/0/threaded http://www.securityfocus.com/bid/21710 http://www.vupen.com/english/advisories/2006/5133

Share on: