CVE-2006-2688: SQL Injection
Published May 31, 2006
·Updated
SQL injection vulnerability in the employees node (class.employee.inc) in Achievo 1.1.0 and earlier and 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the atkselector parameter.
Affected Software
2 affected components
Achievo Achievo=1.1.0
Achievo Achievo=1.2.0
Remediation
Patch Available
Patch Available
Event History
May 31, 2006
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-2688?
CVE-2006-2688 is considered a critical vulnerability due to its potential for remote SQL injection attacks.
2
How do I fix CVE-2006-2688?
To fix CVE-2006-2688, upgrade to Achievo version 1.2.1 or later to mitigate the SQL injection vulnerability.
3
What systems are affected by CVE-2006-2688?
CVE-2006-2688 affects Achievo versions 1.1.0 and earlier, as well as 1.2 and earlier.
4
What kind of attack can exploit CVE-2006-2688?
CVE-2006-2688 can be exploited by attackers to execute arbitrary SQL commands on the database.
5
Is CVE-2006-2688 easy to exploit?
Yes, CVE-2006-2688 is relatively easy to exploit due to the SQL injection nature of the vulnerability.