CVE Vulnerabilities

CVE-2006-2826

Published: Jun 05, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

SQL injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a allows remote attackers to execute arbitrary SQL commands via the id variable, which is set by a client through a query string or a cookie.

Affected Software

NameVendorStart VersionEnd Version
PhplibPhplib_team7.4 (including)7.4 (including)
PhplibPhplib_team7.4_pre2 (including)7.4_pre2 (including)

References