CVE-2006-5322: SQL Injection
Published Oct 17, 2006
·Updated
Multiple SQL injection vulnerabilities in phplist before 2.10.3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected Software
6 affected components
Tincan Phplist=2.9.4
Tincan Phplist=2.9.3
Tincan Phplist=2.8.12
Tincan Phplist=2.9.5
Tincan Phplist=2.10.1
Tincan Phplist<=2.10.2
Event History
Oct 17, 2006
CVE Published
05:07 PM
Data Sourced
via NVD·05:07 PM
DescriptionSeverityAffected Software
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-5322?
CVE-2006-5322 is considered a critical vulnerability due to its potential to allow remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2006-5322?
To fix CVE-2006-5322, upgrade PHPList to version 2.10.3 or later to mitigate the identified SQL injection vulnerabilities.
3
What versions of PHPList are affected by CVE-2006-5322?
CVE-2006-5322 affects PHPList versions 2.8.12 and 2.9.3 through 2.10.2.
4
Can CVE-2006-5322 lead to data exposure?
Yes, CVE-2006-5322 can lead to unauthorized data exposure as attackers can manipulate SQL queries to access sensitive data.
5
Is it safe to use PHPList versions earlier than 2.10.3 after the discovery of CVE-2006-5322?
No, using PHPList versions earlier than 2.10.3 is not safe as they are vulnerable to SQL injection attacks.