7.5
CVSSv2

CVE-2006-3940

Published: 31/07/2006 Updated: 17/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in phpbb-Auction allow remote malicious users to execute arbitrary SQL commands via (1) the ar parameter in auction_room.php and (2) the u parameter in auction_store.php. NOTE: the auction_rating.php vector is already covered by CVE-2005-1234. NOTE: the original disclosure states that the product name is "PHP-Auction", but this is probably an error.

Vulnerable Product Search on Vulmon Subscribe to Product

phpbb group phpbb-auction 1.3m

phpbb group phpbb-auction 1.0m

phpbb group phpbb-auction 1.2m

Exploits

source: wwwsecurityfocuscom/bid/19179/info PHPBB-Auction is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in an SQL query These vulnerabilities could permit remote attackers to pass malicious input to database queries, resulting in the modificatio ...
source: wwwsecurityfocuscom/bid/19179/info PHPBB-Auction is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in an SQL query These vulnerabilities could permit remote attackers to pass malicious input to database queries, resulting in the modification ...