First published: Wed Oct 18 2006(Updated: )
SQL injection vulnerability in index.php in WebSPELL 4.01.01 and earlier allows remote attackers to execute arbitrary SQL commands via the getsquad parameter, a different vector than CVE-2006-4783.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webspell | =4.0 | |
Webspell | =4.01.01 | |
=4.0 | ||
=4.01.01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5388 is considered a critical SQL injection vulnerability that allows attackers to execute arbitrary SQL commands.
To fix CVE-2006-5388, upgrade to WebSPELL version 4.01.02 or later, which addresses this vulnerability.
WebSPELL versions 4.0 and 4.01.01 are affected by CVE-2006-5388.
Yes, CVE-2006-5388 can be exploited remotely by attackers to gain unauthorized access to the database.
CVE-2006-5388 facilitates SQL injection attacks that can compromise the security of the application.