CVE-2006-2590: SQL Injection
Published May 25, 2006
·Updated
SQL injection vulnerability in e107 before 0.7.5 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.
Affected Software
1 affected component
e107 e107=0.7.5
Remediation
Patch Available
Patch Available
Event History
May 25, 2006
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-2590?
CVE-2006-2590 is considered to have a high severity due to its potential for remote SQL command execution.
2
How do I fix CVE-2006-2590?
To fix CVE-2006-2590, upgrade to e107 version 0.7.5 or later.
3
What types of attacks can exploit CVE-2006-2590?
CVE-2006-2590 allows attackers to execute arbitrary SQL commands through unvalidated input.
4
Which versions of e107 are affected by CVE-2006-2590?
CVE-2006-2590 affects e107 versions prior to 0.7.5.
5
Is there a patch available for CVE-2006-2590?
Yes, upgrading to e107 version 0.7.5 provides a patch for CVE-2006-2590.