CVE Vulnerabilities

CVE-2006-5736

Published: Nov 06, 2006 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

SQL injection vulnerability in search.php in PunBB before 1.2.14, when the PHP installation is vulnerable to CVE-2006-3017, allows remote attackers to execute arbitrary SQL commands via the result_list array parameter, which is not initialized.

Affected Software

NameVendorStart VersionEnd Version
PunbbPunbb*1.2.13 (including)
PunbbPunbb1.0 (including)1.0 (including)
PunbbPunbb1.0.1 (including)1.0.1 (including)
PunbbPunbb1.0_alpha (including)1.0_alpha (including)
PunbbPunbb1.0_beta1 (including)1.0_beta1 (including)
PunbbPunbb1.0_beta1a (including)1.0_beta1a (including)
PunbbPunbb1.0_beta2 (including)1.0_beta2 (including)
PunbbPunbb1.0_beta3 (including)1.0_beta3 (including)
PunbbPunbb1.0_rc1 (including)1.0_rc1 (including)
PunbbPunbb1.0_rc2 (including)1.0_rc2 (including)
PunbbPunbb1.1 (including)1.1 (including)
PunbbPunbb1.1.1 (including)1.1.1 (including)
PunbbPunbb1.1.2 (including)1.1.2 (including)
PunbbPunbb1.1.3 (including)1.1.3 (including)
PunbbPunbb1.1.4 (including)1.1.4 (including)
PunbbPunbb1.1.5 (including)1.1.5 (including)
PunbbPunbb1.2 (including)1.2 (including)
PunbbPunbb1.2.1 (including)1.2.1 (including)
PunbbPunbb1.2.2 (including)1.2.2 (including)
PunbbPunbb1.2.3 (including)1.2.3 (including)
PunbbPunbb1.2.4 (including)1.2.4 (including)
PunbbPunbb1.2.5 (including)1.2.5 (including)
PunbbPunbb1.2.6 (including)1.2.6 (including)
PunbbPunbb1.2.7 (including)1.2.7 (including)
PunbbPunbb1.2.8 (including)1.2.8 (including)
PunbbPunbb1.2.9 (including)1.2.9 (including)
PunbbPunbb1.2.10 (including)1.2.10 (including)
PunbbPunbb1.2.11 (including)1.2.11 (including)
PunbbPunbb1.2.12 (including)1.2.12 (including)

References