Vulnerabilities > CVE-2006-1849 - Input Validation vulnerability in xFlow

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
skymarx-solutions

Summary

Multiple SQL injection vulnerabilities in members_only/index.cgi in xFlow 5.46.11 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) position and (2) id parameter.

Vulnerable Configurations

Part Description Count
Application
Skymarx_Solutions
1