CVE-2006-6706: SQL Injection
SQL injection vulnerability in Soumu Workflow for Groupmax 01-00 through 01-01, Soumu Workflow 02-00 through 03-03, and Koukyoumuke Soumu Workflow 01-00 through 01-01 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors in certain web pages.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be authenticated to the affected application and able to reach the vulnerable web pages. The issue is remotely exploitable and does not require a low-complexity attack path beyond access to those pages.
Which deployments are known to be affected?
Affected versions are Soumu Workflow for Groupmax 01-00 through 01-01, Soumu Workflow 02-00 through 03-03, and Koukyoumuke Soumu Workflow 01-00 through 01-01.
What could an attacker do after exploiting it?
A successful attacker can execute arbitrary SQL commands through unspecified vectors in certain web pages. The reported impact includes partial compromise of confidentiality, integrity, and availability.