CVE-2006-0774
DB_eSession < 1.0.2 - SQL Injection via $_sess_id_set Variable
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-0774. PoCs published by GulfTech Security.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in DB_eSession by manipulating the PHPSESSID cookie. The payload bypasses authentication by injecting a malformed session ID with a trailing SQL comment.
Description
SQL injection vulnerability in deleteSession() in DB_eSession library 1.0.2 and earlier, as used in multiple products, allows remote attackers to execute arbitrary SQL commands via the $_sess_id_set variable, which is usually derived from PHPSESSID.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in DB_eSession by manipulating the PHPSESSID cookie. The payload bypasses authentication by injecting a malformed session ID with a trailing SQL comment.