← Back

CVE-2006-3139

nvd nist
Published: Jun 22, 2006Modified: Apr 16, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Multiple SQL injection vulnerabilities in war.php in Virtual War (VWar) 1.5.0 R14 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) s, (2) showgame, (3) sortorder, and (4) sortby parameters.

Affected (14)

Products: Vwar: Virtual War
1 product
Virtual War
Configuration A
14 vulnerable
Vulnerable SoftwareAffected Versions
Vwar
Up to 1.5.0_r14
Version 1.5.0_r10
Version 1.5.0_r11
Version 1.5.0_r12
Version 1.5.0_r13
Version 1.5.0_r1
Version 1.5.0_r2
Version 1.5.0_r3
Version 1.5.0_r4
Version 1.5.0_r5
Version 1.5.0_r6
Version 1.5.0_r7
Version 1.5.0_r8
Version 1.5.0_r9

References (20)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.