CVE-2006-2416: SQL Injection
Published May 16, 2006
·Updated
SQL injection vulnerability in class2.php in e107 0.7.2 and earlier allows remote attackers to execute arbitrary SQL commands via a cookie as defined in $pref['cookiename'].
Affected Software
18 affected components
e107 e107=0.6175
e107 e107=0.616
e107 e107=0.6_15
e107 e107=0.555_beta
e107 e107=0.7.2
e107 e107=0.554
e107 e107=0.6_10
e107 e107=0.545
e107 e107=0.7
e107 e107=0.6_12
e107 e107=0.7.1
e107 e107=0.6_13
e107 e107=0.603
e107 e107=0.6_15a
e107 e107=0.6_14
e107 e107=0.617
e107 e107=0.6171
e107 e107=0.6_11
Remediation
Patch Available
Patch Available
Event History
May 16, 2006
CVE Published
10:02 AM
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-2416?
CVE-2006-2416 is considered a high severity vulnerability due to its potential for executing arbitrary SQL commands.
2
How do I fix CVE-2006-2416?
To fix CVE-2006-2416, upgrade to a version of e107 later than 0.7.2 that includes security patches.
3
Which versions are affected by CVE-2006-2416?
CVE-2006-2416 affects e107 versions up to and including 0.7.2.
4
What type of vulnerability is CVE-2006-2416?
CVE-2006-2416 is an SQL injection vulnerability.
5
Can CVE-2006-2416 be exploited remotely?
Yes, CVE-2006-2416 can be exploited remotely via manipulated cookies.