CVE-2006-6157

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
28/11/2006
Last modified:
09/04/2025

Description

SQL injection vulnerability in index.php in ContentNow 1.39 and earlier allows remote attackers to execute arbitrary SQL commands via the pageid parameter. NOTE: this issue can be leveraged for path disclosure with an invalid pageid parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:michaelis_freunde:contentnow:*:*:*:*:*:*:*:* 1.39 (including)