CVE-2006-0942
pwsphp < 1.2.3 - SQL Injection via profil.php aff_news_form Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-0942. PoCs published by papipsycho.
AI-analyzed exploit summary This exploit leverages an SQL injection vulnerability in PwsPHP 1.2.3 to modify user data, including elevating privileges by setting the 'grade' field to 4 (admin). The exploit crafts a malicious form submission to 'profil.php' with injected SQL in the 'aff_news_form' parameter.
Description
SQL injection vulnerability in profil.php in PwsPHP 1.2.3, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the aff_news_form parameter, a different vulnerability than CVE-2005-1509.
Exploits (1)
This exploit leverages an SQL injection vulnerability in PwsPHP 1.2.3 to modify user data, including elevating privileges by setting the 'grade' field to 4 (admin). The exploit crafts a malicious form submission to 'profil.php' with injected SQL in the 'aff_news_form' parameter.