CVE

Id
22281  
CVE No.
CVE-2006-6177  
Status
Candidate  
Description
SQL injection vulnerability in system/core/users/users.profile.inc.php in Neocrome Seditio 1.10 and earlier allows remote authenticated users to execute arbitrary SQL commands via a double-url-encoded id parameter to users.php that begins with a valid filename, as demonstrated by "default.gif" followed by an encoded NULL and " (apostrophe) (%2500%2527).  
Phase
Assigned (20061130)  
Votes
None (candidate not yet proposed)  
Comments