Multiple SQL injection vulnerabilities in show.php in BirthSys 3.1 allow...
Vulnerability Description
Multiple SQL injection vulnerabilities in show.php in BirthSys 3.1 allow remote attackers to execute arbitrary SQL commands via the $month variable. NOTE: a vector regarding the $date parameter and data.php (date.php) was originally reported, but this appears to be in error.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-0775
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.osvdb.org/23185
- http://www.vupen.com/english/advisories/2006/0621
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24617
- http://securityreason.com/securityalert/467
- http://attrition.org/pipermail/vim/2006-February/000549.html
- http://www.evuln.com/vulns/74/summary.html
- http://secunia.com/advisories/18893
- http://www.securityfocus.com/bid/16684
Affected Vendor
ridder roeland
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.