CVE-2006-1495
PHPCollab 2.4-2.5.rc3, NetOffice 2.5.3-pl1-2.6.0b2 - SQL Injection
Title source: llmDescription
SQL injection vulnerability in general/sendpassword.php in (1) PHPCollab 2.4 and 2.5.rc3, and (2) NetOffice 2.5.3-pl1 and 2.6.0b2 allows remote attackers to execute arbitrary SQL commands via the loginForm parameter in the "forgotten password" option.
Exploits (1)
Scores
EPSS
0.0541
EPSS Percentile
90.2%
Details
Status
published
Products (3)
netoffice/netoffice
2.5.3_pl1
phpcollab/phpcollab
2.4
phpcollab/phpcollab
2.5.rc3
Published
Mar 30, 2006
Tracked Since
Feb 18, 2026