CVE Vulnerabilities

CVE-2006-3190

Published: Jun 23, 2006 | Modified: Oct 18, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

SQL injection vulnerability in administration/includes/login/auth.php in HotPlug CMS 1.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password parameters.

Affected Software

Name Vendor Start Version End Version
Hotplug_cms Hotplug_cms 1.0 (including) 1.0 (including)

References