Vulnerability Name: | CVE-2006-3139 (CCN-27153) | ||||||||
Assigned: | 2006-06-15 | ||||||||
Published: | 2006-06-15 | ||||||||
Updated: | 2018-10-18 | ||||||||
Summary: | Multiple SQL injection vulnerabilities in war.php in Virtual War (VWar) 1.5.0 R14 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) s, (2) showgame, (3) sortorder, and (4) sortby parameters. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-89 | ||||||||
Vulnerability Consequences: | Data Manipulation | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Thu Aug 03 2006 - 01:16:55 CDT Vwar v1.5.0 <= Sql Injection and XSS vuln. Source: BUGTRAQ Type: UNKNOWN 20080213 Vwar New Bug Source: MITRE Type: CNA CVE-2006-3139 Source: MITRE Type: CNA CVE-2006-4010 Source: MITRE Type: CNA CVE-2006-4225 Source: CCN Type: UNSECURED SYSTEMS 06/15/2006 Virtual War multiple SQL inj. vuln. Source: MISC Type: UNKNOWN http://pridels0.blogspot.com/2006/06/virtual-war-multiple-sql-inj-vuln.html Source: CCN Type: SA20696 Virtual War "war.php" Cross-Site Scripting and SQL Injection Source: SECUNIA Type: Vendor Advisory 20696 Source: OSVDB Type: UNKNOWN 26533 Source: CCN Type: OSVDB ID: 26533 Virtual War (Vwar) war.php Multiple Parameter SQL Injection Source: CCN Type: OSVDB ID: 29112 Virtual War (Vwar) war.php Multiple Parameter SQL Injection Source: BUGTRAQ Type: UNKNOWN 20060814 Virtual War v1.5.0 SQL injection and XSS Source: BUGTRAQ Type: UNKNOWN 20080213 Re: Vwar New Bug Source: CCN Type: BID-19327 VWar Multiple Input Validation Vulnerabilities Source: BID Type: UNKNOWN 27772 Source: CCN Type: BID-27772 REITRED: VWar 'war.php' Multiple SQL Injection Vulnerabilities Source: VUPEN Type: Vendor Advisory ADV-2006-2383 Source: CCN Type: Vwar-Virtual War Web site VWar 1.5.0 R14 Source: XF Type: UNKNOWN virtualwar-war-sql-injection(27153) Source: XF Type: UNKNOWN virtualwar-war-sql-injection(27153) Source: XF Type: UNKNOWN virtualwar-warphp-sql-injection(40481) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |