CVE-2006-5388: SQL Injection
Published Oct 18, 2006
·Updated
SQL injection vulnerability in index.php in WebSPELL 4.01.01 and earlier allows remote attackers to execute arbitrary SQL commands via the getsquad parameter, a different vector than CVE-2006-4783.
Affected Software
2 affected components
webSPELL Webspell=4.0
webSPELL Webspell=4.01.01
Event History
Oct 18, 2006
CVE Published
07:07 PM
Data Sourced
via NVD·07:07 PM
DescriptionSeverityAffected Software
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-5388?
CVE-2006-5388 is considered a critical SQL injection vulnerability that allows attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2006-5388?
To fix CVE-2006-5388, upgrade to WebSPELL version 4.01.02 or later, which addresses this vulnerability.
3
What versions of WebSPELL are affected by CVE-2006-5388?
WebSPELL versions 4.0 and 4.01.01 are affected by CVE-2006-5388.
4
Can CVE-2006-5388 be exploited remotely?
Yes, CVE-2006-5388 can be exploited remotely by attackers to gain unauthorized access to the database.
5
What type of attack does CVE-2006-5388 facilitate?
CVE-2006-5388 facilitates SQL injection attacks that can compromise the security of the application.