CVE-2006-3318
Published Jun 29, 2006
Last updated 6 years ago
Overview
- Description
- SQL injection vulnerability in register.php for phpRaid 3.0.6 and possibly other versions, when the authorization type is phpraid, allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) email parameters.
- Source
- PSIRT-CNA@flexerasoftware.com
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5.1
- Impact score
- 6.4
- Exploitability score
- 4.9
- Vector string
- AV:N/AC:H/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-89
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:spiffyjr:phpraid:3.0.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C2080E07-A725-49A9-AECE-AA3FE5F94867" } ], "operator": "OR" } ] } ]