CVE-2006-0907: SQL Injection
SQL injection vulnerability in PHP-Nuke before 7.8 Patched 3.2 allows remote attackers to execute arbitrary SQL commands via encoded /%2a (/) sequences in the query string, which bypasses regular expressions that are intended to protect against SQL injection, as demonstrated via the kala parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0907?
CVE-2006-0907 is considered a high severity vulnerability due to its ability to allow remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2006-0907?
To fix CVE-2006-0907, upgrade to PHP-Nuke version 7.8 Patched 3.2 or later.
What software is affected by CVE-2006-0907?
CVE-2006-0907 affects PHP-Nuke versions prior to 7.8 Patched 3.2.
What type of attack does CVE-2006-0907 enable?
CVE-2006-0907 enables SQL injection attacks, allowing attackers to manipulate backend databases.
Where can I find more information about CVE-2006-0907?
For more information about CVE-2006-0907, review security advisories and reports from credible sources.