Unrated severityNVD Advisory· Published Jan 9, 2006· Updated Jun 16, 2026
CVE-2006-0135
CVE-2006-0135
Description
SQL injection vulnerability in login.php in TheWebForum (twf) 1.2.1 allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the username parameter (aka the u variable).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:thewebforum:thewebforum:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:thewebforum:thewebforum:*:*:*:*:*:*:*:*range: <=1.2.1
- (no CPE)range: =1.2.1
Patches
Vulnerability mechanics
References
10- evuln.com/vulns/17/exploit.htmlnvdExploit
- evuln.com/vulns/17/summary.htmlnvdExploit
- securitytracker.com/idnvdExploit
- www.securityfocus.com/bid/16161nvdExploit
- secunia.com/advisories/18392nvdVendor Advisory
- securityreason.com/securityalert/321nvd
- www.osvdb.org/22294nvd
- www.securityfocus.com/archive/1/421039/100/0/threadednvd
- www.vupen.com/english/advisories/2006/0093nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/24027nvd
News mentions
0No linked articles in our index yet.