CVE-2006-0679: SQL Injection
Published Feb 16, 2006
·Updated
SQL injection vulnerability in index.php in the YourAccount module in PHP-Nuke 7.8 and earlier allows remote attackers to execute arbitrary SQL commands via the username variable (Nickname field).
Affected Software
1 affected component
Francisco Burzi Php-nuke Ev=7.8
Event History
Feb 16, 2006
CVE Published
08:06 PM
Feb 17, 2006
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0679?
CVE-2006-0679 is classified as a high severity vulnerability due to its potential for arbitrary SQL command execution.
2
How do I fix CVE-2006-0679?
To fix CVE-2006-0679, upgrade to a version of PHP-Nuke later than 7.8 that has patched this vulnerability.
3
What systems are affected by CVE-2006-0679?
CVE-2006-0679 affects PHP-Nuke versions 7.8 and earlier.
4
What type of attack is CVE-2006-0679?
CVE-2006-0679 is an SQL injection vulnerability that allows attackers to manipulate database queries.
5
Can CVE-2006-0679 be exploited remotely?
Yes, CVE-2006-0679 can be exploited remotely by attackers to execute unauthorized SQL commands.