CVE-2006-3318
phpRaid 3.0.6 - SQL Injection via Username or Email Parameter
Title source: llmDescription
SQL injection vulnerability in register.php for phpRaid 3.0.6 and possibly other versions, when the authorization type is phpraid, allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) email parameters.
References (6)
Core 6
Core References
Vendor Advisory x_refsource_misc
http://secunia.com/secunia_research/2006-47/advisory/
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/27459
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2006/2593
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/438706/100/0/threaded
Third Party Advisory third-party-advisory
x_refsource_sreason
http://securityreason.com/securityalert/1173
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/20865
Scores
EPSS
0.0120
EPSS Percentile
65.2%
Details
CWE
CWE-89
Status
published
Products (1)
spiffyjr/phpraid
3.0.6
Published
Jun 29, 2006
Tracked Since
Feb 18, 2026