Vulnerabilities > CVE-2006-0870 - SQL Injection vulnerability in MiniNuke CMS Pages.ASP

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
mini-nuke
exploit available

Summary

SQL injection vulnerability in pages.asp in Mini-Nuke CMS System 1.8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: version 2.3 was later reported to be vulnerable as well.

Vulnerable Configurations

Part Description Count
Application
Mini-Nuke
1

Exploit-Db

descriptionMiniNuke <= 1.8.2b (pages.asp) Remote SQL Injection Exploit. CVE-2006-0870. Webapps exploit for asp platform
idEDB-ID:1514
last seen2016-01-31
modified2006-02-19
published2006-02-19
reporternukedx
sourcehttps://www.exploit-db.com/download/1514/
titleMiniNuke <= 1.8.2b pages.asp Remote SQL Injection Exploit