CVE-2006-2826

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/06/2006
Last modified:
03/04/2025

Description

SQL injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a allows remote attackers to execute arbitrary SQL commands via the id variable, which is set by a client through a query string or a cookie.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:phplib_team:phplib:7.4:*:*:*:*:*:*:*
cpe:2.3:a:phplib_team:phplib:7.4_pre2:*:*:*:*:*:*:*