CVE-2006-2029: SQL Injection
Multiple SQL injection vulnerabilities in Jeremy Ashcraft Simplog 0.9.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) tid parameter in (a) preview.php; the (2) cid, (3) pid, and (4) eid parameters in (b) archive.php; and the (5) pid parameter in (c) comments.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2029?
CVE-2006-2029 is considered to have a medium severity due to its potential for remote SQL injection attacks.
How do I fix CVE-2006-2029?
To fix CVE-2006-2029, upgrade Simplog to version 0.9.4 or later where these vulnerabilities have been addressed.
What are the affected parameters in CVE-2006-2029?
The affected parameters in CVE-2006-2029 include tid in preview.php, cid, pid, and eid in archive.php, and pid in comments.php.
Can CVE-2006-2029 be exploited remotely?
Yes, CVE-2006-2029 allows remote attackers to exploit the vulnerabilities to execute arbitrary SQL commands.
Which version of Simplog is vulnerable to CVE-2006-2029?
Simplog version 0.9.3 and earlier are vulnerable to CVE-2006-2029.