501Third-party advisory
http://securityreason.com/securityalert/501 CVE-2006-0972
Fantastic News 2.1.1 - SQL Injection
Record summary
CVE-2006-0972 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
SQL injection vulnerability in news.php in Tony Baird Fantastic News 2.1.1 allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the category vector is already covered by CVE-2005-3846.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBFantastic News 2.1.1 - SQL InjectionExploitDB exploitby SAUDINot analyzed1 file
References
520060226 2 SQL Injection in Fantastic Newsmailing list
http://www.securityfocus.com/archive/1/426195/100/0/threaded 16842vdb entry
http://www.securityfocus.com/bid/16842 fantasticnews-news-sql-injection(24943)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/24943 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2006-0972