Vulnerabilities > CVE-2006-0823 - Input Validation vulnerability in Geeklog
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Multiple SQL injection vulnerabilities in Geeklog 1.4.0 before 1.4.0sr1 and 1.3.11 before 1.3.11sr4 allow remote attackers to inject arbitrary SQL commands via the (1) userid variable to users.php or (2) sessid variable to lib-sessions.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 5 |
Exploit-Db
description | Geeklog < 1.4.0 - Multiple Vulnerabilities. CVE-2006-0823. Webapps exploit for PHP platform |
id | EDB-ID:43833 |
last seen | 2018-01-24 |
modified | 2016-02-19 |
published | 2016-02-19 |
reporter | Exploit-DB |
source | https://www.exploit-db.com/download/43833/ |
title | Geeklog < 1.4.0 - Multiple Vulnerabilities |
Nessus
NASL family | CGI abuses |
NASL id | GEEKLOG_140SR1.NASL |
description | The installed version of Geeklog suffers from a number of SQL injection and local file flaws due to a failure of the application to sanitize user-supplied input. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 20959 |
published | 2006-02-22 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/20959 |
title | Geeklog < 1.3.11sr4 / 1.4.0sr1 Multiple Remote Vulnerabilities (LFI, SQLi) |
code |
|
References
- http://secunia.com/advisories/18920
- http://www.geeklog.net/article.php/geeklog-1.4.0sr1
- http://www.gulftech.org/?node=research&article_id=00102-02192006
- http://www.osvdb.org/23348
- http://www.securityfocus.com/archive/1/425506/100/0/threaded
- http://www.securityfocus.com/bid/16755
- http://www.vupen.com/english/advisories/2006/0661
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24775