CVE-2006-3275: SQL Injection
Published Jun 28, 2006
·Updated
SQL injection vulnerability in profile.php in YaBB SE 1.5.5 and earlier allows remote attackers to execute SQL commands via a double-encoded user parameter in a viewprofile action.
Affected Software
4 affected components
Yabb Yabb<=1.5.5
Yabb Yabb=1.5.1
Yabb Yabb=1.5.2
Yabb Yabb=1.5.4
Event History
Jun 28, 2006
CVE Published
10:05 PM
Jun 29, 2006
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-3275?
CVE-2006-3275 is considered a medium severity vulnerability due to its potential for SQL injection attacks.
2
How do I fix CVE-2006-3275?
To fix CVE-2006-3275, upgrade to YaBB SE version 1.5.6 or later, which addresses this vulnerability.
3
What software is affected by CVE-2006-3275?
CVE-2006-3275 affects YaBB SE versions 1.5.5 and earlier, specifically 1.5.1, 1.5.2, and 1.5.4.
4
What type of vulnerability is CVE-2006-3275?
CVE-2006-3275 is an SQL injection vulnerability that allows attackers to execute arbitrary SQL commands.
5
How does CVE-2006-3275 impact web applications?
CVE-2006-3275 can lead to unauthorized data access, manipulation, or deletion in web applications that use vulnerable versions of YaBB.