CVE-2006-3148: SQL Injection
Published Jun 22, 2006
·Updated
SQL injection vulnerability, possibly in search.inc.php, in Open-Realty 2.3.1 allows remote attackers to execute arbitrary SQL commands via the sorttype parameter to index.php.
Affected Software
1 affected component
Open-Realty Open-Realty=2.3.1
Event History
Jun 22, 2006
CVE Published
10:06 PM
Jun 23, 2006
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-3148?
CVE-2006-3148 is classified as a high severity vulnerability due to its potential for SQL injection attacks.
2
How do I fix CVE-2006-3148?
To fix CVE-2006-3148, upgrade Open-Realty to a version that is not affected by this SQL injection vulnerability.
3
What type of vulnerability is CVE-2006-3148?
CVE-2006-3148 is an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands.
4
In which software is CVE-2006-3148 found?
CVE-2006-3148 is found in Open-Realty version 2.3.1.
5
What parameters are involved in CVE-2006-3148?
CVE-2006-3148 involves the 'sorttype' parameter in the index.php file.