Security Advisory

CVE-2006-6880

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2007-01-05 02:00:00
Last updated 2024-08-07 20:42:07
Assigner mitre
State PUBLISHED

Description

Multiple SQL injection vulnerabilities in code/guestadd.php in PHP-Update 2.7 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) newmessage, (2) newname, (3) newwebsite, or (4) newemail parameter.