TROYANOSYVIRUS
Volver a CVEs

CVE-2006-3994

N/A

Descripcion

SQL injection vulnerability in the u2u_send_recp function in u2u.inc.php in XMB (aka extreme message board) 1.9.6 Alpha and earlier allows remote attackers to execute arbitrary SQL commands via the u2uid parameter to u2u.php, which is directly accessed from $_POST and bypasses the protection scheme.

Detalles CVE

Puntuacion CVSS v3.1N/A
Publicado8/5/2006
Ultima modificacion4/16/2026
Fuentenvd
Avistamientos honeypot0

Productos afectados

xmb_software:xmb_forum

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.