First published: Tue Mar 28 2006(Updated: )
Multiple SQL injection vulnerabilities in akocomment.php in AkoComment 2.0 module for Mambo, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) acname or (2) contentid parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Arthur Konze Webdesign Akocomment | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1421 is considered a critical vulnerability due to its potential for remote SQL injection.
To fix CVE-2006-1421, ensure that magic_quotes_gpc is enabled or update to a patched version of AkoComment that resolves the SQL injection issues.
CVE-2006-1421 affects users of AkoComment 2.0 for Mambo without the magic_quotes_gpc setting enabled.
Attackers can exploit CVE-2006-1421 through the acname or contentid parameters in akocomment.php to execute arbitrary SQL commands.
CVE-2006-1421 was disclosed in April 2006.