Vulnerabilities > CVE-2004-2263 - SQL Injection vulnerability in Anton Raharja PlaySMS Valid Function

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
playsms
exploit available

Summary

SQL injection vulnerability in the valid function in fr_left.php in PlaySMS 0.7 and earlier allows remote attackers to modify SQL statements via the vc2 cookie.

Vulnerable Configurations

Part Description Count
Application
Playsms
2

Exploit-Db

descriptionPlaySMS. CVE-2004-2263. Remote exploit for linux platform
idEDB-ID:404
last seen2016-01-31
modified2004-08-19
published2004-08-19
reporterNoam Rathaus
sourcehttps://www.exploit-db.com/download/404/
titlePlaySMS <= 0.7 - SQL Injection Exploit