Vulnerabilities > CVE-2006-0774 - SQL Injection vulnerability in Lawrence Osiris DB_eSession Class
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
SQL injection vulnerability in deleteSession() in DB_eSession library 1.0.2 and earlier, as used in multiple products, allows remote attackers to execute arbitrary SQL commands via the $_sess_id_set variable, which is usually derived from PHPSESSID.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Lawrence Osiris DB_eSession 1.0.2 Class SQL Injection Vulnerability. CVE-2006-0774 . Webapps exploit for php platform |
id | EDB-ID:27202 |
last seen | 2016-02-03 |
modified | 2006-02-13 |
published | 2006-02-13 |
reporter | GulfTech Security |
source | https://www.exploit-db.com/download/27202/ |
title | Lawrence Osiris DB_eSession 1.0.2 Class SQL Injection Vulnerability |
References
- http://secunia.com/advisories/18805
- http://www.gulftech.org/?node=research&article_id=00099-02112006
- http://www.osvdb.org/23104
- http://www.securityfocus.com/archive/1/424819/100/0/threaded
- http://www.securityfocus.com/archive/1/433132/30/5160/threaded
- http://www.securityfocus.com/bid/16598
- http://www.vupen.com/english/advisories/2006/0528
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24673