18624Third-party advisory
http://secunia.com/advisories/18624 CVE-2006-0413
NewsPHP - 'index.php' Multiple SQL Injections
Record summary
CVE-2006-0413 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Multiple SQL injection vulnerabilities in index.php in NewsPHP allow remote attackers to execute arbitrary SQL commands via the (1) discuss, (2) tim, (3) id, (4) last, and (5) limit parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBNewsPHP - 'index.php' Multiple SQL InjectionsExploitDB exploitby SAUDINot analyzed1 file
References
722717vdb entry
http://www.osvdb.org/22717 20060122 Newsphp Multiple SQL Injection Vulnerabilitiesmailing list
http://www.securityfocus.com/archive/1/423129/100/0/threaded 16339vdb entry
http://www.securityfocus.com/bid/16339 ADV-2006-0341vdb entry
http://www.vupen.com/english/advisories/2006/0341 newsphp-index-sql-injection(24320)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/24320 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2006-0413