Vulnerabilities > CVE-2006-0851 - SQL Injection vulnerability in IlchClan

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
ilch-de
exploit available

Summary

SQL injection vulnerability in the forum module of ilchClan 1.05g and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter, when creating a newpost.

Exploit-Db

descriptionilchClan <= 1.05g (tid) Remote SQL Injection Exploit. CVE-2006-0851. Webapps exploit for php platform
fileexploits/php/webapps/1516.php
idEDB-ID:1516
last seen2016-01-31
modified2006-02-20
platformphp
port
published2006-02-20
reporterx128
sourcehttps://www.exploit-db.com/download/1516/
titleilchClan <= 1.05g tid Remote SQL Injection Exploit
typewebapps