CVE-2006-1947
NicPlex Plexum < X5 - SQL Injection via pagesize maxrec or startpos Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-1947. PoCs published by r0t.
AI-analyzed exploit summary The provided text describes SQL injection vulnerabilities in Plexum X5, detailing vulnerable parameters in the 'plexum.php' script. It includes example URLs demonstrating how unsanitized input in 'startpos', 'maxrec', and 'pagesize' parameters can be exploited.
Description
Multiple SQL injection vulnerabilities in plexum.php in NicPlex Plexum X5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) pagesize, (2) maxrec, and (3) startpos parameters.
Exploits (1)
The provided text describes SQL injection vulnerabilities in Plexum X5, detailing vulnerable parameters in the 'plexum.php' script. It includes example URLs demonstrating how unsanitized input in 'startpos', 'maxrec', and 'pagesize' parameters can be exploited.