Title : Etomite "username" Parameter Handling Remote SQL Injection Vulnerability VUPEN ID : VUPEN/ADV-2006-2961 CVE ID : CVE-2006-3904
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-07-25
Technical Description
A vulnerability has been identified in Etomite, which may be exploited by attackers to execute arbitrary SQL commands. This flaw is due to an input validation error in the "manager/index.php" script that does not validate the "username" variable before being used in SQL statements, which could be exploited by malicious people to conduct SQL injection attacks.