First published: Thu Feb 16 2006(Updated: )
SQL injection vulnerability in search.php in webSPELL 4.01.00 and earlier allows remote attackers to inject arbitrary SQL commands via the title_op parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webspell | <=4.01.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0728 has a medium severity level due to its potential for SQL injection attacks.
To fix CVE-2006-0728, update webSPELL to the latest version beyond 4.01.00 which addresses this vulnerability.
CVE-2006-0728 affects webSPELL versions 4.01.00 and earlier.
Yes, CVE-2006-0728 can allow attackers to execute arbitrary SQL commands, potentially leading to unauthorized access.
Yes, there are known exploits that demonstrate SQL injection through the title_op parameter in affected versions of webSPELL.