CVE-2006-3940: SQL Injection
Multiple SQL injection vulnerabilities in phpbb-Auction allow remote attackers to execute arbitrary SQL commands via (1) the ar parameter in auctionroom.php and (2) the u parameter in auctionstore.php. NOTE: the auctionrating.php vector is already covered by CVE-2005-1234. NOTE: the original disclosure states that the product name is "PHP-Auction", but this is probably an error.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3940?
CVE-2006-3940 is considered a high severity vulnerability due to the potential for remote SQL command execution.
How do I fix CVE-2006-3940?
To fix CVE-2006-3940, you should update phpBB-Auction to a version that has patched the SQL injection vulnerabilities.
Which versions of phpBB-Auction are affected by CVE-2006-3940?
CVE-2006-3940 affects phpBB-Auction versions 1.0m, 1.2m, and 1.3m.
What types of attacks are enabled by CVE-2006-3940?
CVE-2006-3940 enables remote attackers to execute arbitrary SQL commands via vulnerable parameters.
Is CVE-2006-3940 related to any other vulnerabilities?
Yes, CVE-2006-3940 includes vulnerabilities that are distinct but related to those covered by CVE-2005-1234.