19609Third-party advisory
http://secunia.com/advisories/19609 CVE-2006-1708
Clansys 1.1 (showid) - SQL Injection
Record summary
CVE-2006-1708 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
SQL injection vulnerability in member.php in Clansys 1.1 allows remote attackers to execute arbitrary SQL commands via the showid parameter in the member page to index.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBClansys 1.1 (showid) - SQL InjectionExploitDB exploitby snatcherNot analyzed1 file
References
71015935vdb entry
http://securitytracker.com/id?1015935 17456vdb entry
http://www.securityfocus.com/bid/17456 ADV-2006-1295vdb entry
http://www.vupen.com/english/advisories/2006/1295 clansys-index-sql-injection(25746)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/25746 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2006-1708 1662exploit
https://www.exploit-db.com/exploits/1662