CVE-2006-3559: SQL Injection
Published Jul 13, 2006
·Updated
Multiple SQL injection vulnerabilities in Arif Supriyanto auraCMS 1.62 allow remote attackers to execute arbitrary SQL commands and delete all shoutbox messages via the (1) name and (2) pesan parameters.
Affected Software
1 affected component
Arif Supriyanto auraCMS=1.62
Event History
Jul 13, 2006
CVE Published
12:05 AM
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-3559?
CVE-2006-3559 is considered to have a high severity due to its potential for remote SQL execution.
2
How do I fix CVE-2006-3559?
To fix CVE-2006-3559, you should sanitize and validate all user inputs for the name and pesan parameters.
3
What types of attacks can be performed due to CVE-2006-3559?
CVE-2006-3559 allows attackers to execute arbitrary SQL commands, which may lead to data deletion and unauthorized data access.
4
Which versions of auraCMS are affected by CVE-2006-3559?
CVE-2006-3559 affects auraCMS version 1.62.
5
Who is the publisher of auraCMS vulnerable to CVE-2006-3559?
The publisher of the vulnerable auraCMS 1.62 is Arif Supriyanto.