CVE Vulnerabilities

CVE-2006-3828

Published: Jul 25, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Incomplete blacklist vulnerability in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allows remote authenticated administrators to bypass SQL injection protection mechanisms by using commas, quote characters, pound sign (#) characters, UNION, and SELECT, which are not filtered by the product, which only checks for insert, delete, update, and replace.

Affected Software

NameVendorStart VersionEnd Version
BoastmachineKailash_nadh2.5 (including)2.5 (including)
BoastmachineKailash_nadh2.7 (including)2.7 (including)
BoastmachineKailash_nadh2.8 (including)2.8 (including)
BoastmachineKailash_nadh2.9b (including)2.9b (including)
BoastmachineKailash_nadh3.1 (including)3.1 (including)

References