Vulnerabilities > CVE-2006-1849 - Unspecified vulnerability in Skymarx Solutions Xflow
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Multiple SQL injection vulnerabilities in members_only/index.cgi in xFlow 5.46.11 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) position and (2) id parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- http://pridels0.blogspot.com/2006/04/xflow-v5x-multiple-vuln.html
- http://pridels0.blogspot.com/2006/04/xflow-v5x-multiple-vuln.html
- http://secunia.com/advisories/19707
- http://secunia.com/advisories/19707
- http://www.securityfocus.com/bid/17614
- http://www.securityfocus.com/bid/17614
- http://www.vupen.com/english/advisories/2006/1412
- http://www.vupen.com/english/advisories/2006/1412
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25853
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25853