![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2006-3292 |
Description: | SQL injection vulnerability in the Search gadget in Jaws 0.6.2 allows remote attackers to execute arbitrary SQL commands via queries with the "LIKE" keyword in the searchdata parameter (search field). |
Test IDs: | None available |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2006-3292 BugTraq ID: 18665 http://www.securityfocus.com/bid/18665 Bugtraq: 20060626 Jaws <= 0.6.2 'Search gadget' SQL injection (Google Search) http://www.securityfocus.com/archive/1/438434/100/0/threaded http://retrogod.altervista.org/JAWS_062_sql.html http://secunia.com/advisories/20842 http://securityreason.com/securityalert/1165 http://www.vupen.com/english/advisories/2006/2546 XForce ISS Database: jaws-search-gadget-sql-injection(27334) https://exchange.xforce.ibmcloud.com/vulnerabilities/27334 |