Multiple SQL injection vulnerabilities in BytesFall Explorer (bfExplorer) 0.0.7.1 and earlier allow remote attackers to execute arbitrary SQL commands via the username ($User variable) to login/doLogin.php and other unspecified vectors.
References
Configurations
Information
Published : 2006-10-31 11:07
Updated : 2018-10-17 14:43
NVD link : CVE-2006-5606
Mitre link : CVE-2006-5606
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
bytesfall_explorer
- bytesfall_explorer