CVE-2006-4606

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
07/09/2006
Last modified:
17/10/2018

Description

Multiple SQL injection vulnerabilities in Longino Jacome php-Revista 1.1.2 allow remote attackers to execute arbitrary SQL commands via the (1) id_temas parameter in busqueda_tema.php, the (2) cadena parameter in busqueda.php, the (3) id_autor parameter in autor.php, the (4) email parameter in lista.php, and the (5) id_articulo parameter in articulo.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:longino:jacome_php-revista:1.1.2:*:*:*:*:*:*:*