CVE-2006-0942

pwsphp < 1.2.3 - SQL Injection via profil.php aff_news_form Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-0942. PoCs published by papipsycho.

AI-analyzed exploit summary This exploit leverages an SQL injection vulnerability in PwsPHP 1.2.3 to modify user data, including elevating privileges by setting the 'grade' field to 4 (admin). The exploit crafts a malicious form submission to 'profil.php' with injected SQL in the 'aff_news_form' parameter.

Description

SQL injection vulnerability in profil.php in PwsPHP 1.2.3, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the aff_news_form parameter, a different vulnerability than CVE-2005-1509.

Exploits (1)

exploitdb WORKING POC VERIFIED
by papipsycho · phpwebappsphp
https://www.exploit-db.com/exploits/27175

This exploit leverages an SQL injection vulnerability in PwsPHP 1.2.3 to modify user data, including elevating privileges by setting the 'grade' field to 4 (admin). The exploit crafts a malicious form submission to 'profil.php' with injected SQL in the 'aff_news_form' parameter.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: PwsPHP 1.2.3
Auth required
Prerequisites: Valid user credentials · Magic quotes disabled · Access to the target's profil.php endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/28444
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/16567

Scores

EPSS 0.0112
EPSS Percentile 62.0%

Details

Status published
Products (1)
pwsphp/pwsphp < 1.2.3
Published Mar 01, 2006
Tracked Since Feb 18, 2026