{ "schema_version": "1.4.0", "id": "GHSA-684j-qvrf-6fvq", "modified": "2022-05-01T06:51:29Z", "published": "2022-05-01T06:51:29Z", "aliases": [ "CVE-2006-1638" ], "details": "Multiple SQL injection vulnerabilities in aWebBB 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) Username parameter to (a) accounts.php, (b) changep.php, (c) editac.php, (d) feedback.php, (e) fpass.php, (f) login.php, (g) post.php, (h) reply.php, or (i) reply_log.php; (2) p parameter to (j) dpost.php; (3) c parameter to (k) list.php or (l) ndis.php; or (12) q parameter to (m) search.php.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2006-1638" }, { "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/25587" }, { "type": "WEB", "url": "http://evuln.com/vulns/117/summary.html" }, { "type": "WEB", "url": "http://secunia.com/advisories/19486" }, { "type": "WEB", "url": "http://www.osvdb.org/24340" }, { "type": "WEB", "url": "http://www.osvdb.org/24341" }, { "type": "WEB", "url": "http://www.osvdb.org/24342" }, { "type": "WEB", "url": "http://www.osvdb.org/24343" }, { "type": "WEB", "url": "http://www.osvdb.org/24344" }, { "type": "WEB", "url": "http://www.osvdb.org/24345" }, { "type": "WEB", "url": "http://www.osvdb.org/24346" }, { "type": "WEB", "url": "http://www.osvdb.org/24347" }, { "type": "WEB", "url": "http://www.osvdb.org/24348" }, { "type": "WEB", "url": "http://www.osvdb.org/24349" }, { "type": "WEB", "url": "http://www.osvdb.org/24350" }, { "type": "WEB", "url": "http://www.osvdb.org/24351" }, { "type": "WEB", "url": "http://www.osvdb.org/24352" }, { "type": "WEB", "url": "http://www.securityfocus.com/archive/1/431064/100/0/threaded" }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/17352" }, { "type": "WEB", "url": "http://www.vupen.com/english/advisories/2006/1197" } ], "database_specific": { "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2006-04-06T10:04:00Z" } }