CVE-2006-2835
saphplesson 2.0 - SQL Injection via forumid or lessid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-2835. PoCs published by C.B.B.L.
AI-analyzed exploit summary The provided text describes an SQL injection vulnerability in SaPHPLesson, where the 'forumid' parameter in 'add.php' is not properly sanitized. This allows attackers to manipulate SQL queries, potentially compromising the application or underlying database.
Description
SQL injection vulnerability in saphplesson 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) forumid parameter in add.php and (2) lessid parameter in show.php.
Exploits (1)
The provided text describes an SQL injection vulnerability in SaPHPLesson, where the 'forumid' parameter in 'add.php' is not properly sanitized. This allows attackers to manipulate SQL queries, potentially compromising the application or underlying database.