CVE-2006-4734: SQL Injection
Multiple SQL injection vulnerabilities in tiki-g-adminprocesses.php in Tikiwiki 1.9.4 allow remote attackers to execute arbitrary SQL commands via the (1) pid and (2) where parameters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4734?
CVE-2006-4734 is considered a high severity vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2006-4734?
To fix CVE-2006-4734, it is recommended to upgrade to a more secure version of Tikiwiki that is not susceptible to SQL injection vulnerabilities.
What causes CVE-2006-4734?
CVE-2006-4734 is caused by improper validation of user input in the tiki-g-admin_processes.php file, allowing SQL commands to be executed by attackers.
Who is affected by CVE-2006-4734?
CVE-2006-4734 affects users of Tikiwiki version 1.9.4 specifically.
What are the potential impacts of exploiting CVE-2006-4734?
Exploiting CVE-2006-4734 can allow remote attackers to execute arbitrary SQL commands, compromising the integrity and confidentiality of the database.