Record summary

CVE-2006-3940 has a selected CVSS score of 7.5; EIP currently links 2 catalogued exploits.

Description

Multiple SQL injection vulnerabilities in phpbb-Auction allow remote attackers to execute arbitrary SQL commands via (1) the ar parameter in auction_room.php and (2) the u parameter in auction_store.php. NOTE: the auction_rating.php vector is already covered by CVE-2005-1234. NOTE: the original disclosure states that the product name is "PHP-Auction", but this is probably an error.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

Proofs of concept

2

Catalogued exploits

ExploitDBphpBB-Auction 1.x - 'auction_room.php?ar' SQL InjectionExploitDB exploitby l2odonNot analyzed1 file
ExploitDB

PoC details
ExploitDBphpBB-Auction 1.x - 'auction_store.php?u' SQL InjectionExploitDB exploitby l2odonNot analyzed1 file
ExploitDB

PoC details

References

6