18885Third-party advisory
http://secunia.com/advisories/18885 CVE-2006-0728
webSPELL 4.01 - 'title_op' SQL Injection
Record summary
CVE-2006-0728 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
SQL injection vulnerability in search.php in webSPELL 4.01.00 and earlier allows remote attackers to inject arbitrary SQL commands via the title_op parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBwebSPELL 4.01 - 'title_op' SQL InjectionExploitDB exploitby x128Not analyzed1 file
References
616673vdb entry
http://www.securityfocus.com/bid/16673 ADV-2006-0606vdb entry
http://www.vupen.com/english/advisories/2006/0606 webspell.orgConfirmation
http://www.webspell.org/index.php?site=news_comments&newsID=49&lang=en webspell-search-sql-injection(24708)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/24708 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2006-0728