CVE-2006-5107: SQL Injection
Published Oct 3, 2006
·Updated
Multiple SQL injection vulnerabilities in Devellion CubeCart 2.0.x allow remote attackers to execute arbitrary SQL commands via (1) the username parameter in admin/forgotpass.php, (2) the orderid parameter in vieworder.php, (3) the viewdoc parameter in viewdoc.php, and (4) the orderid parameter in admin/printorder.php.
Affected Software
7 affected components
Devellion CubeCart=2.0.3
Devellion CubeCart=2.0.4
Devellion CubeCart=2.0.1
Devellion CubeCart=2.0.2
Devellion CubeCart=2.0.5
Devellion CubeCart=2.0.6
Devellion CubeCart=2.0.0
Event History
Oct 3, 2006
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:03 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2006-5107?
CVE-2006-5107 is a high severity vulnerability that allows remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2006-5107?
To fix CVE-2006-5107, upgrade CubeCart to a version that is not affected, such as 2.0.6 or later.
3
Which versions of CubeCart are affected by CVE-2006-5107?
CVE-2006-5107 affects CubeCart versions 2.0.0 through 2.0.5.
4
What types of attacks can CVE-2006-5107 enable?
CVE-2006-5107 can enable SQL injection attacks that compromise database security.
5
Is authentication required to exploit CVE-2006-5107?
No, CVE-2006-5107 can be exploited by unauthenticated remote attackers.