CVE-2006-3135

N/A Unknown
Published: July 13, 2006 Modified: April 16, 2026
View on NVD

Description

Multiple SQL injection vulnerabilities in CMS Mundo 1.0 build 008, and possibly other versions, allow remote attackers to execute arbitrary SQL commands via the (1) news_id parameter in the (a) news module, (2) searchstring parameter in (b) the search module, (3) id parameter in (c) the webshop module, (4) username parameter in (d) index.php, and (5) Name, (6) Address, (7) Zip, (8) City, (9) Country, and (10) Email fields during (e) a user profile update.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://secunia.com/advisories/20589
Source: PSIRT-CNA@flexerasoftware.com
Exploit Vendor Advisory
http://secunia.com/secunia_research/2006-52/advisory/
Source: PSIRT-CNA@flexerasoftware.com
Vendor Advisory
http://securityreason.com/securityalert/1236
Source: PSIRT-CNA@flexerasoftware.com
http://www.osvdb.org/27139
Source: PSIRT-CNA@flexerasoftware.com
http://www.osvdb.org/27140
Source: PSIRT-CNA@flexerasoftware.com
http://www.osvdb.org/27141
Source: PSIRT-CNA@flexerasoftware.com
http://www.osvdb.org/27142
Source: PSIRT-CNA@flexerasoftware.com
http://www.osvdb.org/27143
Source: PSIRT-CNA@flexerasoftware.com
http://www.vupen.com/english/advisories/2006/2783
Source: PSIRT-CNA@flexerasoftware.com
http://secunia.com/advisories/20589
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit Vendor Advisory
http://secunia.com/secunia_research/2006-52/advisory/
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://securityreason.com/securityalert/1236
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/27139
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/27140
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/27141
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/27142
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/27143
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2006/2783
Source: af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/27712
Source: af854a3a-2127-422b-91ae-364da2661108

20 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
2.2%
85th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

hotwebscripts