Multiple SQL injection vulnerabilities in BytesFall Explorer (bfExplorer) 0.0.7.1 and earlier allow remote attackers to execute arbitrary SQL commands via the username ($User variable) to login/doLogin.php and other unspecified vectors.
References
Configurations
History
No history.
Information
Published : 2006-10-31 19:07
Updated : 2018-10-17 21:43
NVD link : CVE-2006-5606
Mitre link : CVE-2006-5606
CVE.ORG link : CVE-2006-5606
JSON object : View
Products Affected
bytesfall_explorer
- bytesfall_explorer
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')