CVE-2006-6369: SQL Injection
SQL injection vulnerability in lib/entryreplyentry.php in Invision Community Blog Mod 1.2.4 allows remote attackers to execute arbitrary SQL commands via the eid parameter, when accessed through the "Preview message" functionality.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6369?
CVE-2006-6369 is considered to be a high severity vulnerability due to its potential to allow remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2006-6369?
To fix CVE-2006-6369, you should update to a patched version of Invision Community Blog Mod that addresses this SQL injection flaw.
What versions are affected by CVE-2006-6369?
CVE-2006-6369 specifically affects Invision Community Blog Mod version 1.2.4.
Can CVE-2006-6369 lead to data breaches?
Yes, exploiting CVE-2006-6369 can potentially lead to data breaches by allowing unauthorized access to the database.
What type of attack utilizes CVE-2006-6369?
CVE-2006-6369 is exploited through SQL injection attacks that manipulate the eid parameter via the 'Preview message' functionality.