{ "id": "CVE-2006-3111", "sourceIdentifier": "cve@mitre.org", "published": "2006-06-21T01:02:00.000", "lastModified": "2024-11-21T00:12:50.690", "vulnStatus": "Modified", "cveTags": [], "descriptions": [ { "lang": "en", "value": "Multiple SQL injection vulnerabilities in main.php in Chipmailer 1.09 allow remote attackers to execute arbitrary SQL commands via multiple parameters, as demonstrated by (1) anfang, (2) name, (3) mail, (4) anrede, (5) vorname, (6) nachname, (7) gebtag, (8) gebmonat, and (9) gebjahr." }, { "lang": "es", "value": "M\u00faltiples vulnerabilidades de inyecci\u00f3n SQL en main.php en Chipmailer v1.09 permite a atacantes remotos ejecutar comandos SQL a trav\u00e9s de varios par\u00e1metros, como se demostr\u00f3 por (1) anfang, (2) name, (3) name, (4) Anrede, (5) Vorname, (6) nachname, (7) gebtag, (8) gebmonat y (9) gebjahr." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P", "baseScore": 7.5, "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "availabilityImpact": "PARTIAL" }, "baseSeverity": "HIGH", "exploitabilityScore": 10.0, "impactScore": 6.4, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": true, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "NVD-CWE-Other" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:chipmailer:chipmailer:1.09:*:*:*:*:*:*:*", "matchCriteriaId": "1E8DCDC9-BB69-4573-88B2-90873DDD5B58" } ] } ] } ], "references": [ { "url": "http://marc.info/?l=bugtraq&m=115024576618386&w=2", "source": "cve@mitre.org" }, { "url": "http://secunia.com/advisories/20643", "source": "cve@mitre.org", "tags": [ "Vendor Advisory" ] }, { "url": "http://securitytracker.com/id?1016315", "source": "cve@mitre.org" }, { "url": "http://www.securityfocus.com/bid/18463", "source": "cve@mitre.org" }, { "url": "http://www.vupen.com/english/advisories/2006/2359", "source": "cve@mitre.org" }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27158", "source": "cve@mitre.org" }, { "url": "http://marc.info/?l=bugtraq&m=115024576618386&w=2", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://secunia.com/advisories/20643", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] }, { "url": "http://securitytracker.com/id?1016315", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://www.securityfocus.com/bid/18463", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://www.vupen.com/english/advisories/2006/2359", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27158", "source": "af854a3a-2127-422b-91ae-364da2661108" } ] }