CVE-2006-0669
N/A
N/A
Summary
Multiple SQL injection vulnerabilities in archive.asp in GA's Forum Light allow remote attackers to execute arbitrary SQL commands via the (1) Forum and (2) pages parameter. NOTE: SecurityTracker says that the vendor has disputed this issue, saying that GA Forum Light does not use an SQL database. SecurityTracker's research indicates that the original problem could be due to a vbscript parsing error based on invalid arguments
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.securityfocus.com/bid/16563
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24616
- http://securitytracker.com/id?1015600
- http://www.attrition.org/pipermail/vim/2006-February/000561.html
- http://www.osvdb.org/23509
References
- http://www.securityfocus.com/bid/16563
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24616
- http://securitytracker.com/id?1015600
- http://www.attrition.org/pipermail/vim/2006-February/000561.html
- http://www.osvdb.org/23509
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.