CVE-2006-6116: SQL Injection
Published Nov 26, 2006
·Updated
SQL injection vulnerability in default2.asp in fipsForum 2.6 and earlier allows remote attackers to execute arbitrary SQL commands via the kat parameter.
Affected Software
1 affected component
fipsASP Fipsforum<=2.6
Event History
Nov 26, 2006
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:07 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2006-6116?
CVE-2006-6116 is considered a high-severity vulnerability due to its potential for remote exploitation.
2
How do I fix CVE-2006-6116?
To fix CVE-2006-6116, upgrade to a version of fipsForum later than 2.6 that does not contain the SQL injection vulnerability.
3
What type of vulnerability is CVE-2006-6116?
CVE-2006-6116 is an SQL injection vulnerability that allows attackers to execute arbitrary SQL commands.
4
Which versions of fipsForum are affected by CVE-2006-6116?
CVE-2006-6116 affects fipsForum version 2.6 and earlier.
5
How can attackers exploit CVE-2006-6116?
Attackers can exploit CVE-2006-6116 by manipulating the kat parameter in default2.asp to execute unauthorized SQL commands.