CVE
- Id
- 21733
- CVE No.
- CVE-2006-5629
- Status
- Candidate
- Description
- Multiple SQL injection vulnerabilities in Hosting Controller 6.1 before Hotfix 3.3 allow remote attackers to execute arbitrary SQL commands via the ForumID parameter in (1) DisableForum.asp and (2) enableForum.asp. NOTE: it was later reported that the vulnerability is present in 6.1 Hotfix 3.3 and earlier.
- Phase
- Assigned (20061031)
- Votes
- None (candidate not yet proposed)
- Comments