![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2006-0913 |
Description: | SQL injection vulnerability in whineatnews.pl in Bugzilla 2.17 through 2.18.4 and 2.20 allows remote authenticated users with administrative privileges to execute arbitrary SQL commands via the whinedays parameter, as accessible from editparams.cgi. |
Test IDs: | None available |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2006-0913 BugTraq ID: 16738 http://www.securityfocus.com/bid/16738 Bugtraq: 20060221 [BUGZILLA] Security Advisory for Bugzilla 2.20, 2.21.1, and 2.18.4 (Google Search) http://www.securityfocus.com/archive/1/425584/100/0/threaded http://www.osvdb.org/23378 http://secunia.com/advisories/18979 http://www.vupen.com/english/advisories/2006/0692 XForce ISS Database: bugzilla-editparams-sql-injection(24819) https://exchange.xforce.ibmcloud.com/vulnerabilities/24819 |