PT-2006-1747 · Calimba · Calimba

Aliaksandr Hartsuyeu

·

Published

2006-02-15

·

Updated

2018-10-19

·

CVE-2006-0693

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CALimba versions 0.99.2 beta and earlier
Description The issue allows remote attackers to execute arbitrary SQL commands and bypass login authentication. This is achieved via the login and password parameters in the rb auth.php file.
Recommendations For versions 0.99.2 beta and earlier, update to a version that fixes the SQL injection vulnerabilities in the rb auth.php file to prevent remote attackers from executing arbitrary SQL commands and bypassing login authentication.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-0693

Affected Products

Calimba