CVE-2006-0913: SQL Injection
Published Feb 28, 2006
·Updated
SQL injection vulnerability in whineatnews.pl in Bugzilla 2.17 through 2.18.4 and 2.20 allows remote authenticated users with administrative privileges to execute arbitrary SQL commands via the whinedays parameter, as accessible from editparams.cgi.
Affected Software
22 affected components
Bugzilla=2.17.1
Bugzilla=2.17.3
Bugzilla=2.17.4
Bugzilla=2.17.5
Bugzilla=2.17.6
Bugzilla=2.17.7
Bugzilla=2.18-rc1
Bugzilla=2.18-rc2
Bugzilla=2.18-rc3
Bugzilla=2.18.1
Bugzilla=2.18.2
Bugzilla=2.18.3
Bugzilla=2.18.4
Bugzilla=2.19
Bugzilla=2.19.1
Bugzilla=2.19.2
Bugzilla=2.19.3
Bugzilla=2.20
Bugzilla=2.20-rc1
Bugzilla=2.20-rc2
Bugzilla=2.21
Bugzilla=2.21.1
Remediation
Patch Available
Event History
Feb 28, 2006
CVE Published
11:02 AM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0913?
CVE-2006-0913 is considered a medium severity vulnerability due to its ability to allow unauthorized SQL commands execution.
2
How do I fix CVE-2006-0913?
To fix CVE-2006-0913, upgrade Bugzilla to version 2.18.5 or later.
3
Which versions of Bugzilla are affected by CVE-2006-0913?
CVE-2006-0913 affects Bugzilla versions 2.17 to 2.20-rc2.
4
What type of vulnerability is CVE-2006-0913?
CVE-2006-0913 is an SQL injection vulnerability.
5
Who can exploit CVE-2006-0913?
CVE-2006-0913 can be exploited by authenticated users with administrative privileges.