CVE-2006-2954

Publication date

2006-06-12 20:00:00

Family

mitre

State

PUBLISHED

Description

SQL injection vulnerability in files.asp in OfficeFlow 2.6 and earlier allows remote attackers to execute arbitrary SQL commands via the Project parameter.