CVE-2006-1330: SQL Injection
Published Mar 21, 2006
·Updated
Multiple SQL injection vulnerabilities in phpWebsite 0.83 and earlier allow remote attackers to execute arbitrary SQL commands via the sid parameter to (1) friend.php or (2) article.php.
Affected Software
3 affected components
phpWebSite phpWebSite=0.7.3
phpWebSite phpWebSite=0.8.2
phpWebSite phpWebSite=0.8.3
Event History
Mar 21, 2006
CVE Published
01:06 AM
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1330?
CVE-2006-1330 has a high severity rating due to its potential to allow remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2006-1330?
To fix CVE-2006-1330, upgrade phpWebsite to version 0.8.4 or later, which addresses these vulnerabilities.
3
What software is affected by CVE-2006-1330?
CVE-2006-1330 affects phpWebsite versions 0.7.3, 0.8.2, and 0.8.3.
4
Can CVE-2006-1330 lead to data breaches?
Yes, CVE-2006-1330 can lead to data breaches as it allows attackers to manipulate the database by executing arbitrary SQL commands.
5
What is the primary exploit method for CVE-2006-1330?
The primary exploit method for CVE-2006-1330 is through SQL injection via the sid parameter in friend.php and article.php.