CVE Vulnerabilities

CVE-2006-1495

Published: Mar 30, 2006 | Modified: Oct 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

SQL injection vulnerability in general/sendpassword.php in (1) PHPCollab 2.4 and 2.5.rc3, and (2) NetOffice 2.5.3-pl1 and 2.6.0b2 allows remote attackers to execute arbitrary SQL commands via the loginForm parameter in the forgotten password option.

Affected Software

Name Vendor Start Version End Version
Netoffice Netoffice 2.5.3_pl1 (including) 2.5.3_pl1 (including)
Phpcollab Phpcollab 2.4 (including) 2.4 (including)
Phpcollab Phpcollab 2.5.rc3 (including) 2.5.rc3 (including)

References