CVE Vulnerabilities

CVE-2006-2499

Published: May 20, 2006 | Modified: Oct 18, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

SQL injection vulnerability in default.asp in CodeAvalanche News (CANews) 1.2 allows remote attackers to execute arbitrary SQL commands via the password field.

Affected Software

Name Vendor Start Version End Version
Codeavalanche_news Xfairguy 1.2 (including) 1.2 (including)

References