CVE-2006-5638
phpmyring < 4.2.1 - SQL Injection via cherche.php limite or mots Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-5638. PoCs published by ajann.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in PHP My Ring <= 4.2.1 via the 'limite' parameter in cherche.php, allowing an attacker to extract user credentials (pseudo and mdp) from the 'webring' table.
Description
Multiple SQL injection vulnerabilities in cherche.php in PHPMyRing 4.2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) limite and (2) mots parameters.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in PHP My Ring <= 4.2.1 via the 'limite' parameter in cherche.php, allowing an attacker to extract user credentials (pseudo and mdp) from the 'webring' table.