Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2006-3152
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-3152

Description:
Multiple SQL injection vulnerabilities in phpTRADER 4.9 SP5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) sectio parameter in (a) login.php, (b) write_newad.php, (c) newad.php, (d) printad.php, (e) askseller.php, (f) browse.php, (g) showmemberads.php, (h) note_ad.php, (i) abuse.php, (j) buynow.php, (k) confirm_newad.php, (2) an parameter in (l) printad.php, (m) note_ad.php, (3) who parameter in (n) showmemberads.php, and (4) adnr parameter in (o) buynow.php.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/27267

ST
  1016356

SAID
  Secunia Advisory: SA20740

OSVDB
  26705
  26704
  26703
  26702
  26701
  26700
  26699
  26698
  26697
  26696
  26706

MISC
  http://pridels.blogspot.com/2006/06/phptrader-multiple-sql-injection-vuln.html

BID
  18468


Return to the previous page.