Vulnerabilities > CVE-2006-0774 - SQL Injection vulnerability in Lawrence Osiris DB_eSession Class

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
lawrence-osiris
exploit available

Summary

SQL injection vulnerability in deleteSession() in DB_eSession library 1.0.2 and earlier, as used in multiple products, allows remote attackers to execute arbitrary SQL commands via the $_sess_id_set variable, which is usually derived from PHPSESSID.

Vulnerable Configurations

Part Description Count
Application
Lawrence_Osiris
1

Exploit-Db

descriptionLawrence Osiris DB_eSession 1.0.2 Class SQL Injection Vulnerability. CVE-2006-0774 . Webapps exploit for php platform
idEDB-ID:27202
last seen2016-02-03
modified2006-02-13
published2006-02-13
reporterGulfTech Security
sourcehttps://www.exploit-db.com/download/27202/
titleLawrence Osiris DB_eSession 1.0.2 Class SQL Injection Vulnerability