Xoops · Myads · CVE-2006-3341
**Name of the Vulnerable Software and Affected Versions**
MyAds module version 2.04jp for Xoops
**Description**
The issue allows remote attackers to execute arbitrary SQL commands. This is achieved by exploiting the `lid` parameter in the annonces-p-f.php file.
**Recommendations**
For MyAds module version 2.04jp, avoid using the `lid` parameter in the annonces-p-f.php file until a fix is available. Consider restricting access to the annonces-p-f.php file to minimize the risk of exploitation.