Required CVE Record Information
Description
Multiple SQL injection vulnerabilities in the Google Gadget login.php (gadget/login.php) in Rob Hensley ackerTodo 4.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) up_login, (2) up_pass, or (3) up_num_tasks parameters.
References 10 Total
- securityfocus.com: 20061005 ackerTodo 4.2 SQL Injection Vulnerability mailing-list
- securityreason.com: 1703 third-party-advisory
- http://ackertodo.cvs.sourceforge.net/ackertodo/ackertodo/src/gadget/login.php?view=log
- secunia.com: 22254 third-party-advisory
- securityfocus.com: 20372 vdb-entry
- exchange.xforce.ibmcloud.com: ackertodo-login-sql-injection(29375) vdb-entry
- osvdb.org: 29552 vdb-entry
- vupen.com: ADV-2006-3951 vdb-entry
- securitytracker.com: 1017008 vdb-entry
- http://ackertodo.cvs.sourceforge.net/ackertodo/ackertodo/src/gadget/login.php?r1=1.3&r2=1.4
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 10 Total
- securityfocus.com: 20061005 ackerTodo 4.2 SQL Injection Vulnerability mailing-listx_transferred
- securityreason.com: 1703 third-party-advisoryx_transferred
- http://ackertodo.cvs.sourceforge.net/ackertodo/ackertodo/src/gadget/login.php?view=log x_transferred
- secunia.com: 22254 third-party-advisoryx_transferred
- securityfocus.com: 20372 vdb-entryx_transferred
- exchange.xforce.ibmcloud.com: ackertodo-login-sql-injection(29375) vdb-entryx_transferred
- osvdb.org: 29552 vdb-entryx_transferred
- vupen.com: ADV-2006-3951 vdb-entryx_transferred
- securitytracker.com: 1017008 vdb-entryx_transferred
- http://ackertodo.cvs.sourceforge.net/ackertodo/ackertodo/src/gadget/login.php?r1=1.3&r2=1.4 x_transferred