CVE-2006-1278

N/A Unknown
Published: March 19, 2006 Modified: April 16, 2026
View on NVD

Description

SQL injection vulnerability in @1 File Store 2006.03.07 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) functions.php and (2) user.php in the libs directory, (3) edit.php and (4) delete.php in control/files/, (5) edit.php and (6) delete.php in control/users/, (7) edit.php, (8) access.php, and (9) in control/folders/, (10) access.php and (11) delete.php in control/groups/, (12) confirm.php, and (13) download.php; (14) the email parameter in password.php, and (15) the id parameter in folder.php. NOTE: it was later reported that vectors 12 and 13 also affect @1 File Store PRO 3.2.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://evuln.com/vulns/95/summary.html
Source: cve@mitre.org
Exploit
http://osvdb.org/47017
Source: cve@mitre.org
http://osvdb.org/47018
Source: cve@mitre.org
http://secunia.com/advisories/19224
Source: cve@mitre.org
Vendor Advisory
http://secunia.com/advisories/31063
Source: cve@mitre.org
Vendor Advisory
http://securityreason.com/securityalert/619
Source: cve@mitre.org
Exploit
http://securitytracker.com/id?1015826
Source: cve@mitre.org
Exploit
http://www.osvdb.org/23851
Source: cve@mitre.org
Exploit
http://www.osvdb.org/23852
Source: cve@mitre.org
http://www.osvdb.org/23853
Source: cve@mitre.org
http://www.osvdb.org/23854
Source: cve@mitre.org
http://www.osvdb.org/23855
Source: cve@mitre.org
http://www.osvdb.org/23856
Source: cve@mitre.org
http://www.osvdb.org/23857
Source: cve@mitre.org
http://www.osvdb.org/23858
Source: cve@mitre.org
http://www.osvdb.org/23859
Source: cve@mitre.org
http://www.osvdb.org/23860
Source: cve@mitre.org
http://www.osvdb.org/23861
Source: cve@mitre.org
http://www.osvdb.org/23862
Source: cve@mitre.org
http://www.osvdb.org/23863
Source: cve@mitre.org
http://www.osvdb.org/23864
Source: cve@mitre.org
http://www.osvdb.org/24106
Source: cve@mitre.org
http://www.securityfocus.com/bid/30182
Source: cve@mitre.org
Exploit
http://www.vupen.com/english/advisories/2006/0943
Source: cve@mitre.org
Vendor Advisory
http://evuln.com/vulns/95/summary.html
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
http://osvdb.org/47017
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/47018
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/19224
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/31063
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://securityreason.com/securityalert/619
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
http://securitytracker.com/id?1015826
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
http://www.attrition.org/pipermail/vim/2009-August/002246.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/23851
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
http://www.osvdb.org/23852
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/23853
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/23854
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/23855
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/23856
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/23857
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/23858
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/23859
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/23860
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/23861
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/23862
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/23863
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/23864
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/24106
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/428659/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/17090
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/30182
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
http://www.vupen.com/english/advisories/2006/0943
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/25183
Source: af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/43718
Source: af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/43724
Source: af854a3a-2127-422b-91ae-364da2661108
https://www.exploit-db.com/exploits/6040
Source: af854a3a-2127-422b-91ae-364da2661108

62 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
2.6%
86th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

upoint