PT-2006-4652 · Ufo2000 · Ufo2000

Luigi Auriemma

·

Published

2006-07-21

·

Updated

2018-10-17

·

CVE-2006-3792

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions UFO2000 version prior to svn 1058
Description The issue allows remote attackers to execute arbitrary SQL commands. This is achieved through unspecified vectors involving the packet.c str function in the ServerClientUfo::recv packet function in server protocol.cpp.
Recommendations For UFO2000 version prior to svn 1058, update to a version that includes the fix for this issue to prevent the execution of arbitrary SQL commands.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-3792

Affected Products

Ufo2000