CVE Vulnerabilities

CVE-2006-5736

Published: Nov 06, 2006 | Modified: Oct 17, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

SQL injection vulnerability in search.php in PunBB before 1.2.14, when the PHP installation is vulnerable to CVE-2006-3017, allows remote attackers to execute arbitrary SQL commands via the result_list array parameter, which is not initialized.

Affected Software

Name Vendor Start Version End Version
Punbb Punbb * 1.2.13 (including)
Punbb Punbb 1.0 (including) 1.0 (including)
Punbb Punbb 1.0.1 (including) 1.0.1 (including)
Punbb Punbb 1.0_alpha (including) 1.0_alpha (including)
Punbb Punbb 1.0_beta1 (including) 1.0_beta1 (including)
Punbb Punbb 1.0_beta1a (including) 1.0_beta1a (including)
Punbb Punbb 1.0_beta2 (including) 1.0_beta2 (including)
Punbb Punbb 1.0_beta3 (including) 1.0_beta3 (including)
Punbb Punbb 1.0_rc1 (including) 1.0_rc1 (including)
Punbb Punbb 1.0_rc2 (including) 1.0_rc2 (including)
Punbb Punbb 1.1 (including) 1.1 (including)
Punbb Punbb 1.1.1 (including) 1.1.1 (including)
Punbb Punbb 1.1.2 (including) 1.1.2 (including)
Punbb Punbb 1.1.3 (including) 1.1.3 (including)
Punbb Punbb 1.1.4 (including) 1.1.4 (including)
Punbb Punbb 1.1.5 (including) 1.1.5 (including)
Punbb Punbb 1.2 (including) 1.2 (including)
Punbb Punbb 1.2.1 (including) 1.2.1 (including)
Punbb Punbb 1.2.2 (including) 1.2.2 (including)
Punbb Punbb 1.2.3 (including) 1.2.3 (including)
Punbb Punbb 1.2.4 (including) 1.2.4 (including)
Punbb Punbb 1.2.5 (including) 1.2.5 (including)
Punbb Punbb 1.2.6 (including) 1.2.6 (including)
Punbb Punbb 1.2.7 (including) 1.2.7 (including)
Punbb Punbb 1.2.8 (including) 1.2.8 (including)
Punbb Punbb 1.2.9 (including) 1.2.9 (including)
Punbb Punbb 1.2.10 (including) 1.2.10 (including)
Punbb Punbb 1.2.11 (including) 1.2.11 (including)
Punbb Punbb 1.2.12 (including) 1.2.12 (including)

References