CVE-2006-3994
Last modified
CVE-2006-3994 is a vulnerability of currently unknown severity. SQL injection vulnerability in the u2u_send_recp function in u2u.inc.php in XMB (aka extreme message board) 1.9.6 Alpha and earlier allows remote attackers to execute arbitrary SQL commands via the u2uid parameter to u2u.php, which is directly accessed from $_POST and bypasses the protection scheme.. EPSS estimates a 3.73% chance of exploitation in the next 30 days.
Description
SQL injection vulnerability in the u2u_send_recp function in u2u.inc.php in XMB (aka extreme message board) 1.9.6 Alpha and earlier allows remote attackers to execute arbitrary SQL commands via the u2uid parameter to u2u.php, which is directly accessed from $_POST and bypasses the protection scheme.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xmb Software | Xmb Forum | <= 1.9.6_alpha |
References
- http://secunia.com/advisories/21293Vendor Advisory
- http://secunia.com/advisories/21293Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-3994?
How severe is CVE-2006-3994?
How do I fix CVE-2006-3994?
Are you affected by CVE-2006-3994?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
