CVE-2006-0413
NewsPHP - SQL Injection via discuss, tim, id, last, or limit Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-0413. PoCs published by SAUDI.
AI-analyzed exploit summary The exploit demonstrates multiple SQL injection vulnerabilities in NewsPHP by providing crafted URLs that inject SQL queries into various parameters. These can be used to compromise the application or underlying database.
Description
Multiple SQL injection vulnerabilities in index.php in NewsPHP allow remote attackers to execute arbitrary SQL commands via the (1) discuss, (2) tim, (3) id, (4) last, and (5) limit parameter.
Exploits (1)
The exploit demonstrates multiple SQL injection vulnerabilities in NewsPHP by providing crafted URLs that inject SQL queries into various parameters. These can be used to compromise the application or underlying database.