First published: Mon Jul 31 2006(Updated: )
Multiple SQL injection vulnerabilities in phpbb-Auction allow remote attackers to execute arbitrary SQL commands via (1) the ar parameter in auction_room.php and (2) the u parameter in auction_store.php. NOTE: the auction_rating.php vector is already covered by CVE-2005-1234. NOTE: the original disclosure states that the product name is "PHP-Auction", but this is probably an error.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Phpbb Group Phpbb-auction | =1.2m | |
Phpbb Group Phpbb-auction | =1.3m | |
Phpbb Group Phpbb-auction | =1.0m |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3940 is considered a high severity vulnerability due to the potential for remote SQL command execution.
To fix CVE-2006-3940, you should update phpBB-Auction to a version that has patched the SQL injection vulnerabilities.
CVE-2006-3940 affects phpBB-Auction versions 1.0m, 1.2m, and 1.3m.
CVE-2006-3940 enables remote attackers to execute arbitrary SQL commands via vulnerable parameters.
Yes, CVE-2006-3940 includes vulnerabilities that are distinct but related to those covered by CVE-2005-1234.