VYPR
Unrated severityNVD Advisory· Published Jun 22, 2006· Updated Apr 16, 2026

CVE-2006-3139

CVE-2006-3139

Description

Multiple SQL injection vulnerabilities in war.php in Virtual War (VWar) 1.5.0 R14 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) s, (2) showgame, (3) sortorder, and (4) sortby parameters.

Affected products

14
  • Vwar/Virtual War14 versions
    cpe:2.3:a:vwar:virtual_war:*:*:*:*:*:*:*:*+ 13 more
    • cpe:2.3:a:vwar:virtual_war:*:*:*:*:*:*:*:*range: <=1.5.0_r14
    • cpe:2.3:a:vwar:virtual_war:1.5.0_r1:*:*:*:*:*:*:*
    • cpe:2.3:a:vwar:virtual_war:1.5.0_r10:*:*:*:*:*:*:*
    • cpe:2.3:a:vwar:virtual_war:1.5.0_r11:*:*:*:*:*:*:*
    • cpe:2.3:a:vwar:virtual_war:1.5.0_r12:*:*:*:*:*:*:*
    • cpe:2.3:a:vwar:virtual_war:1.5.0_r13:*:*:*:*:*:*:*
    • cpe:2.3:a:vwar:virtual_war:1.5.0_r2:*:*:*:*:*:*:*
    • cpe:2.3:a:vwar:virtual_war:1.5.0_r3:*:*:*:*:*:*:*
    • cpe:2.3:a:vwar:virtual_war:1.5.0_r4:*:*:*:*:*:*:*
    • cpe:2.3:a:vwar:virtual_war:1.5.0_r5:*:*:*:*:*:*:*
    • cpe:2.3:a:vwar:virtual_war:1.5.0_r6:*:*:*:*:*:*:*
    • cpe:2.3:a:vwar:virtual_war:1.5.0_r7:*:*:*:*:*:*:*
    • cpe:2.3:a:vwar:virtual_war:1.5.0_r8:*:*:*:*:*:*:*
    • cpe:2.3:a:vwar:virtual_war:1.5.0_r9:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

10

News mentions

0

No linked articles in our index yet.