CVE-2006-3577

LifeType 1.0.5 - SQL Injection via Date Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-3577. PoCs published by Alejandro Ramos.

AI-analyzed exploit summary This exploit leverages an SQL injection vulnerability in LifeType 1.0.5 to extract admin credentials (username and MD5 password hash) via a crafted UNION-based SQL query. It then attempts to look up the MD5 hash using an external service.

Description

SQL injection vulnerability in index.php in LifeType 1.0.5 allows remote attackers to execute arbitrary SQL commands via the Date parameter in a Default op.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Alejandro Ramos · perlwebappsphp
https://www.exploit-db.com/exploits/28166

This exploit leverages an SQL injection vulnerability in LifeType 1.0.5 to extract admin credentials (username and MD5 password hash) via a crafted UNION-based SQL query. It then attempts to look up the MD5 hash using an external service.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: LifeType 1.0.5
No auth needed
Prerequisites: Target must be running LifeType 1.0.5 · Network access to the target web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/18835

Scores

EPSS 0.0107
EPSS Percentile 60.5%

Details

Status published
Products (1)
lifetype/lifetype 1.0.5
Published Jul 13, 2006
Tracked Since Feb 18, 2026