Vulnerabilities > CVE-2006-1020 - SQL Injection vulnerability in Johnny Vegas Forum 1.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
johnny-vegas

Summary

SQL injection vulnerability in forumlib.php in Johnny_Vegas Vegas Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the postid parameter.

Vulnerable Configurations

Part Description Count
Application
Johnny_Vegas
1

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/44616/EV0090.txt
idPACKETSTORM:44616
last seen2016-12-05
published2006-03-13
reporterAliaksandr Hartsuyeu
sourcehttps://packetstormsecurity.com/files/44616/EV0090.txt.html
titleEV0090.txt