First published: Tue May 16 2006(Updated: )
SQL injection vulnerability in class2.php in e107 0.7.2 and earlier allows remote attackers to execute arbitrary SQL commands via a cookie as defined in $pref['cookie_name'].
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
e107 CMS | =0.6175 | |
e107 CMS | =0.616 | |
e107 CMS | =0.6_15 | |
e107 CMS | =0.555_beta | |
e107 CMS | =0.7.2 | |
e107 CMS | =0.554 | |
e107 CMS | =0.6_10 | |
e107 CMS | =0.545 | |
e107 CMS | =0.7 | |
e107 CMS | =0.6_12 | |
e107 CMS | =0.7.1 | |
e107 CMS | =0.6_13 | |
e107 CMS | =0.603 | |
e107 CMS | =0.6_15a | |
e107 CMS | =0.6_14 | |
e107 CMS | =0.617 | |
e107 CMS | =0.6171 | |
e107 CMS | =0.6_11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2416 is considered a high severity vulnerability due to its potential for executing arbitrary SQL commands.
To fix CVE-2006-2416, upgrade to a version of e107 later than 0.7.2 that includes security patches.
CVE-2006-2416 affects e107 versions up to and including 0.7.2.
CVE-2006-2416 is an SQL injection vulnerability.
Yes, CVE-2006-2416 can be exploited remotely via manipulated cookies.