CVE-2006-1907: SQL Injection
Multiple SQL injection vulnerabilities in myEvent 1.x allow remote attackers to inject arbitrary SQL commands via the eventid parameter to (1) addevent.php or (2) del.php or (3) eventdesc parameter to addevent.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1907?
CVE-2006-1907 is considered a high severity vulnerability due to its ability to allow remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2006-1907?
To fix CVE-2006-1907, it is recommended to upgrade to a version of myEvent that is not vulnerable, specifically version 1.3 or later.
What are the affected components of CVE-2006-1907?
CVE-2006-1907 affects the addevent.php and del.php files in myEvent versions up to and including 1.2.
Can CVE-2006-1907 be exploited remotely?
Yes, CVE-2006-1907 can be exploited remotely by attackers through input manipulations of specific parameters.
What types of attacks are associated with CVE-2006-1907?
CVE-2006-1907 is associated with SQL injection attacks that can lead to unauthorized data access and manipulation.