Unrated severityNVD Advisory· Published Jan 9, 2006· Updated Apr 16, 2026
CVE-2006-0135
CVE-2006-0135
Description
SQL injection vulnerability in login.php in TheWebForum (twf) 1.2.1 allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the username parameter (aka the u variable).
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- evuln.com/vulns/17/exploit.htmlnvdExploit
- evuln.com/vulns/17/summary.htmlnvdExploit
- securitytracker.com/idnvdExploit
- www.securityfocus.com/bid/16161nvdExploit
- secunia.com/advisories/18392nvdVendor Advisory
- securityreason.com/securityalert/321nvd
- www.osvdb.org/22294nvd
- www.securityfocus.com/archive/1/421039/100/0/threadednvd
- www.vupen.com/english/advisories/2006/0093nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/24027nvd
News mentions
0No linked articles in our index yet.