PT-2006-2938 · Unknown · Rechnungszentrale V2

Published

2006-04-21

·

Updated

2024-02-14

·

CVE-2006-1954

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions RechnungsZentrale V2 versions 1.1.3 and earlier
Description The issue allows remote attackers to execute arbitrary SQL commands. This is achieved by exploiting the SQL injection vulnerability in the authent.php4 file, specifically via the User field.
Recommendations For versions 1.1.3 and earlier, update to a version that fixes this issue, as using the vulnerable version allows attackers to execute arbitrary SQL commands. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

CVE-2006-1954

Affected Products

Rechnungszentrale V2