CVE-2006-1419: SQL Injection
Published Mar 28, 2006
·Updated
SQL injection vulnerability in the Calendar module in nuked-klan 1.7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the m parameter to index.php.
Affected Software
9 affected components
Nuked-Klan Nuked-KlaN=1.2
Nuked-Klan Nuked-KlaN=1.4
Nuked-Klan Nuked-KlaN=1.2_beta
Nuked-Klan Nuked-KlaN=1.3
Nuked-Klan Nuked-KlaN=1.5
Nuked-Klan Nuked-KlaN=1.7
Nuked-Klan Nuked-KlaN=1.5_sp2
Nuked-Klan Nuked-KlaN=1.3_beta
Nuked-Klan Nuked-KlaN<=1.7.5
Event History
Mar 28, 2006
CVE Published
08:02 PM
Mar 29, 2006
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1419?
CVE-2006-1419 is considered to have a high severity due to the potential for remote SQL command execution.
2
How do I fix CVE-2006-1419?
To fix CVE-2006-1419, you should upgrade to Nuked-Klan version 1.7.6 or later.
3
What software versions are affected by CVE-2006-1419?
CVE-2006-1419 affects Nuked-Klan versions up to and including 1.7.5.
4
Can CVE-2006-1419 be exploited remotely?
Yes, CVE-2006-1419 can be exploited remotely by attackers to execute arbitrary SQL commands.
5
What actions should be taken if my system is vulnerable to CVE-2006-1419?
If your system is vulnerable to CVE-2006-1419, it is essential to apply patches immediately and review database access controls.