CVE-2006-0721: SQL Injection
Published Feb 16, 2006
·Updated
SQL injection vulnerability in pmlite.php in RunCMS 1.2 and 1.3a allows remote attackers to execute arbitrary SQL commands via the touserid parameter.
Affected Software
3 affected components
Runcms RunCMS=1.3a
Runcms RunCMS=1.2
Runcms RunCMS=1.3a2
Remediation
Patch Available
Event History
Feb 16, 2006
CVE Published
11:02 AM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0721?
CVE-2006-0721 is considered a high severity vulnerability due to the potential for remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2006-0721?
To fix CVE-2006-0721, ensure that input parameters like to_userid are properly validated and sanitized to prevent SQL injection.
3
What software versions are affected by CVE-2006-0721?
CVE-2006-0721 affects RunCMS versions 1.2, 1.3a, and 1.3a2.
4
What type of vulnerability is CVE-2006-0721?
CVE-2006-0721 is an SQL injection vulnerability that allows attackers to manipulate SQL queries.
5
Can CVE-2006-0721 be exploited remotely?
Yes, CVE-2006-0721 can be exploited remotely, allowing attackers to execute arbitrary SQL commands.