CVE-2006-4783: SQL Injection
SQL injection vulnerability in squads.php in WebSPELL 4.01.01 and earlier, when registerglobals is enabled, allows remote attackers to execute arbitrary SQL commands via the squadID parameter.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4783?
CVE-2006-4783 is considered a critical vulnerability due to its exploitation potential for arbitrary SQL command execution.
How do I fix CVE-2006-4783?
To fix CVE-2006-4783, disable register_globals in the PHP configuration and upgrade to a version of WebSPELL later than 4.01.01.
Who is affected by CVE-2006-4783?
CVE-2006-4783 affects users running WebSPELL version 4.01.01 and earlier with register_globals enabled.
What are the risks associated with CVE-2006-4783?
The risks associated with CVE-2006-4783 include unauthorized access to the database and potential data loss or manipulation.
Can CVE-2006-4783 be exploited remotely?
Yes, CVE-2006-4783 can be exploited remotely by attackers through the squadID parameter.