Vulnerabilities > CVE-2006-0920 - SQL Injection vulnerability in OI Email Marketing System 3.0

047910
CVSS 1.7 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
local
low complexity
oi
exploit available

Summary

Oi! Email Marketing System 3.0 (aka Oi! 3) stores the server's FTP password in cleartext on a Configuration web page, which allows local users with superadministrator privileges, or attackers who have obtained access to the web page, to view the password.

Vulnerable Configurations

Part Description Count
Application
Oi
1

Exploit-Db

descriptionOi! Email Marketing System 3.0 Index.PHP SQL Injection Vulnerability. CVE-2006-0920 . Webapps exploit for php platform
idEDB-ID:27303
last seen2016-02-03
modified2006-02-23
published2006-02-23
reporterh4cky0u
sourcehttps://www.exploit-db.com/download/27303/
titleOi! Email Marketing System 3.0 Index.PHP SQL Injection Vulnerability