CVE-2006-4444

Cybozu Garoon - SQL Injection

Title source: rule
STIX 2.1

Description

Multiple SQL injection vulnerabilities in Cybozu Garoon 2.1.0 for Windows allow remote authenticated users to execute arbitrary SQL commands via the (1) tid parameter in the (a) todo/view (aka TODO List View), (b) todo/modify (aka TODO List Modify), or (c) todo/delete functionality; the (2) pid parameter in the (d) workflow/view or (e) workflow/print functionality; the (3) uid parameter in the (f) schedule/user_view, (g) phonemessage/add, (h) phonemessage/history, or (i) schedule/view functionality; the (4) cid parameter in (j) todo/index; the (5) iid parameter in the (k) memo/view or (l) memo/print functionality; or the (6) event parameter in the (m) schedule/view functionality.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Tan Chew Keong · textwebappscgi
https://www.exploit-db.com/exploits/2267

References (12)

Core 12
Core References
Exploit, Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21664
Various Sources x_refsource_misc
http://cybozu.co.jp/products/dl/notice_060825/
Various Sources x_refsource_misc
http://vuln.sg/cybozugaroon-en.html
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/19731
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/28364
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/28363
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/28365
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3399
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/28594
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/28362
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/28361
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/28366

Scores

EPSS 0.0160
EPSS Percentile 81.8%

Details

Status published
Products (1)
cybozu/garoon 2.1.0_for_windows
Published Aug 29, 2006
Tracked Since Feb 18, 2026