PT-2006-5182 · Guder Und Koch Netzwerktechnik · Eichhorn Portal

Mc Iglo

·

Published

2006-08-26

·

Updated

2018-10-17

·

CVE-2006-4377

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Guder und Koch Netzwerktechnik Eichhorn Portal (affected versions not specified)
Description The issue concerns SQL injection vulnerabilities that allow remote attackers to execute arbitrary SQL commands. The attack vectors may include the profil nr and sprache parameters in the main portion of the portal, the suchstring field in suchForm, the GaleryKey and Breadcrumbs parameters in the gallerie module, and the GGBNSaction parameter in the ggbns module.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-4377

Affected Products

Eichhorn Portal