Vulnerabilities > CVE-2006-1328 - SQL Injection vulnerability in Skull-Splitter Download Counter for Wallpapers Count.PHP

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
skull-splitter

Summary

SQL injection vulnerability in count.php in Skull-Splitter PHP Downloadcounter for Wallpapers 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) count_fieldname, (2) url_fieldname, or (3) url parameter.

Vulnerable Configurations

Part Description Count
Application
Skull-Splitter
1

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/45095/EV0105.txt
idPACKETSTORM:45095
last seen2016-12-05
published2006-04-01
reporterAliaksandr Hartsuyeu
sourcehttps://packetstormsecurity.com/files/45095/EV0105.txt.html
titleEV0105.txt