First published: Thu Apr 20 2006(Updated: )
Multiple SQL injection vulnerabilities in myEvent 1.x allow remote attackers to inject arbitrary SQL commands via the event_id parameter to (1) addevent.php or (2) del.php or (3) event_desc parameter to addevent.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Myevent | <=1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1907 is considered a high severity vulnerability due to its ability to allow remote attackers to execute arbitrary SQL commands.
To fix CVE-2006-1907, it is recommended to upgrade to a version of myEvent that is not vulnerable, specifically version 1.3 or later.
CVE-2006-1907 affects the addevent.php and del.php files in myEvent versions up to and including 1.2.
Yes, CVE-2006-1907 can be exploited remotely by attackers through input manipulations of specific parameters.
CVE-2006-1907 is associated with SQL injection attacks that can lead to unauthorized data access and manipulation.