PT-2006-2942 · Wwwthreads · Wwwthreads Rc 3

D3Vil-0X1

+1

·

Published

2006-04-21

·

Updated

2018-10-18

·

CVE-2006-1958

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions WWWThreads RC 3
Description The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via two methods:
  1. the forumreferrer cookie to register.php
  2. the messages parameter in message list.php.
Recommendations For WWWThreads RC 3, update the software to prevent SQL injection attacks, specifically by validating and sanitizing user input for the forumreferrer cookie and the messages parameter. As a temporary workaround, consider restricting access to register.php and message list.php to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1958

Affected Products

Wwwthreads Rc 3