7.5
CVSSv2

CVE-2006-6923

Published: 13/01/2007 Updated: 08/03/2011
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in newsletters/edition.php in bitweaver 1.3.1 and previous versions allows remote malicious users to execute arbitrary SQL commands via the tk parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

bitweaver bitweaver 1.3.1

bitweaver bitweaver 1.1

bitweaver bitweaver 1.1.1_beta

bitweaver bitweaver 1.2.1

Exploits

source: wwwsecurityfocuscom/bid/20988/info Bitweaver is prone to multiple input-validation vulnerabilities because the application fails to sufficiently sanitize user-supplied input These issues include multiple HTML-injection issues and multiple SQL-injection issues A successful exploit of these vulnerabilities could allow an attacke ...