CVE-2006-2018: SQL Injection
SQL injection vulnerability in calendar.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL commands via the eventid parameter. NOTE: the affected version has been disputed by the vendor. It appears that this is the same issue as CVE-2004-0036, which was fixed in 2.3.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2018?
CVE-2006-2018 is classified as a high severity vulnerability due to its potential for arbitrary SQL command execution.
How do I fix CVE-2006-2018?
To fix CVE-2006-2018, upgrade to a patched version of vBulletin that resolves this SQL injection vulnerability.
Which versions of vBulletin are affected by CVE-2006-2018?
CVE-2006-2018 affects vBulletin versions 3.0.0 through 3.0.12.
What type of vulnerability is CVE-2006-2018?
CVE-2006-2018 is an SQL injection vulnerability in the calendar.php file of vBulletin.
Can CVE-2006-2018 be exploited remotely?
Yes, CVE-2006-2018 can be exploited remotely by attackers to execute arbitrary SQL commands.