CVE-2006-6117: SQL Injection
Published Nov 26, 2006
·Updated
SQL injection vulnerability in index1.asp in fipsGallery 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the which parameter.
Affected Software
1 affected component
fipsASP Fipsgallery<=1.5
Event History
Nov 26, 2006
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:07 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2006-6117?
CVE-2006-6117 has a medium severity rating due to its potential for harmful SQL injection attacks.
2
How do I fix CVE-2006-6117?
To fix CVE-2006-6117, update to fipsGallery version 1.6 or later which addresses the SQL injection vulnerability.
3
What is the impact of CVE-2006-6117?
CVE-2006-6117 allows remote attackers to execute arbitrary SQL commands, potentially compromising database integrity.
4
Which software versions are affected by CVE-2006-6117?
CVE-2006-6117 affects fipsGallery version 1.5 and earlier.
5
Can CVE-2006-6117 be exploited remotely?
Yes, CVE-2006-6117 can be exploited remotely by attackers via specially crafted requests.