CVE-2007-3204

NameCVE-2007-3204
DescriptionSQL injection vulnerability in auth.php in Just For Fun Network Management System (JFFNMS) 0.8.4-pre2 allows remote attackers to execute arbitrary SQL commands via the pass parameter. NOTE: this issue reportedly exists because of an initial incomplete fix for CVE-2007-3190. The provenance of this information is unknown; the details are obtained solely from third party information.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Notes

This is an jffnms ID, which has been wrongly reported by an external party,
The data is sufficiently sanitised with the Debian fix for CVE-2007-3192

Search for package or bug name: Reporting problems