CVE-2006-0972
Fantastic News 2.1.1 - SQL Injection via News.php Page Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-0972. PoCs published by SAUDI.
AI-analyzed exploit summary The provided text describes an SQL injection vulnerability in Fantastic News 2.1.1, where the 'page' parameter in 'news.php' is vulnerable to SQLi via pipe character injection. No actual exploit code is present, only a description and example URL.
Description
SQL injection vulnerability in news.php in Tony Baird Fantastic News 2.1.1 allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the category vector is already covered by CVE-2005-3846.
Exploits (1)
The provided text describes an SQL injection vulnerability in Fantastic News 2.1.1, where the 'page' parameter in 'news.php' is vulnerable to SQLi via pipe character injection. No actual exploit code is present, only a description and example URL.