18597Third-party advisory
http://secunia.com/advisories/18597 CVE-2006-0444
Phpclanwebsite 1.23.1 - SQL Injection
Record summary
CVE-2006-0444 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.
Description
SQL injection vulnerability in index.php in Phpclanwebsite (aka PCW) 1.23.1 allows remote attackers to execute arbitrary SQL commands via the (1) par parameter in the post function on the forum page and possibly the (2) poll_id parameter on the poll page. NOTE: the poll_id vector can also allow resultant cross-site scripting (XSS) from an unquoted error message for invalid SQL syntax.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPhpclanwebsite 1.23.1 - SQL InjectionExploitDB exploitby matrix_killerNot analyzed1 file
References
9h4cky0u.org
http://www.h4cky0u.org/advisories/HYSA-2006-002-phpclan.txt 22720vdb entry
http://www.osvdb.org/22720 22722vdb entry
http://www.osvdb.org/22722 20060125 HYSA-2006-002 Phpclanwebsite 1.23.1 Multiple Vulnerabilitiesmailing list
http://www.securityfocus.com/archive/1/423145/100/0/threaded 16391vdb entry
http://www.securityfocus.com/bid/16391 ADV-2006-0342vdb entry
http://www.vupen.com/english/advisories/2006/0342 phpclanwebsite-index-sql-injection(24355)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/24355 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2006-0444