First published: Thu Apr 13 2006(Updated: )
SQL injection vulnerability in index.php in SWSoft Confixx 3.0.6, 3.0.8, and 3.1.2 allows remote attackers to execute arbitrary SQL commands via the SID parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SWSoft Confixx | =3.0.6 | |
SWSoft Confixx | =3.0.8 | |
SWSoft Confixx | =3.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1754 is rated as a high severity vulnerability that allows remote attackers to execute arbitrary SQL commands.
CVE-2006-1754 affects SWSoft Confixx versions 3.0.6, 3.0.8, and 3.1.2.
To mitigate CVE-2006-1754, upgrade to the latest version of SWSoft Confixx that is not vulnerable to this SQL injection.
Yes, CVE-2006-1754 can be exploited remotely by attackers targeting the SID parameter in index.php.
CVE-2006-1754 is an SQL injection vulnerability that allows unauthorized SQL command execution.