Vulnerabilities > CVE-2006-1421 - SQL Injection vulnerability in Arthur Konze Webdesign Akocomment 2.0

047910
CVSS 5.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
high complexity
arthur-konze-webdesign

Summary

Multiple SQL injection vulnerabilities in akocomment.php in AkoComment 2.0 module for Mambo, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) acname or (2) contentid parameter. In order to exploit this vulnerability, the 'magic_quotes_gpc' parameter must be disabled.

Vulnerable Configurations

Part Description Count
Application
Arthur_Konze_Webdesign
1