First published: Fri Jun 16 2006(Updated: )
SQL injection vulnerability in TikiWiki 1.9.3.2 and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tiki Wiki CMS Groupware | =1.9.0-rc2 | |
Tiki Wiki CMS Groupware | =1.9.3 | |
Tiki Wiki CMS Groupware | =1.9.0 | |
Tiki Wiki CMS Groupware | =1.9.0-rc1 | |
Tiki Wiki CMS Groupware | =1.9.0-rc3 | |
Tiki Wiki CMS Groupware | =1.9.2 | |
Tiki Wiki CMS Groupware | =1.9.1 | |
Tiki Wiki CMS Groupware | <=1.9.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3048 is classified as a medium severity SQL injection vulnerability that can allow remote attackers to execute arbitrary SQL commands.
To fix CVE-2006-3048, upgrade to TikiWiki version 1.9.3.2 or later to mitigate the SQL injection vulnerability.
TikiWiki versions 1.9.0 up to 1.9.3.1 are affected by CVE-2006-3048.
Attackers can exploit CVE-2006-3048 to execute arbitrary SQL commands, potentially leading to unauthorized data access.
Yes, CVE-2006-3048 has known exploit vectors that utilize SQL injection to compromise the TikiWiki application.