CVE

Id
18169  
CVE No.
CVE-2006-2065  
Status
Candidate  
Description
SQL injection vulnerability in save.php in PHPSurveyor 0.995 and earlier allows remote attackers to execute arbitrary SQL commands via the surveyid cookie. NOTE: this issue could be leveraged to execute arbitrary PHP code, as demonstrated by inserting directory traversal sequences into the database, which are then processed by the thissurvey["language"] variable.  
Phase
Assigned (20060426)  
Votes
None (candidate not yet proposed)  
Comments