Vulnerabilities > CVE-2006-1481 - Unspecified vulnerability in PHP Ticket PHP Ticket 0.5/0.6
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN php-ticket
exploit available
Summary
SQL injection vulnerability in search.php in PHP Ticket 0.71 allows remote authenticated users to execute arbitrary SQL commands and obtain usernames and passwords via the frm_search_in parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
Exploit-Db
description | PHP Ticket <= 0.71 (search.php) Remote SQL Injection Exploit. CVE-2006-1481. Webapps exploit for php platform |
file | exploits/php/webapps/1609.pl |
id | EDB-ID:1609 |
last seen | 2016-01-31 |
modified | 2006-03-25 |
platform | php |
port | |
published | 2006-03-25 |
reporter | undefined1_ |
source | https://www.exploit-db.com/download/1609/ |
title | PHP Ticket <= 0.71 search.php Remote SQL Injection Exploit |
type | webapps |
References
- http://secunia.com/advisories/19412
- http://secunia.com/advisories/19412
- http://www.securityfocus.com/bid/17229
- http://www.securityfocus.com/bid/17229
- http://www.vupen.com/english/advisories/2006/1106
- http://www.vupen.com/english/advisories/2006/1106
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25436
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25436
- https://www.exploit-db.com/exploits/1609
- https://www.exploit-db.com/exploits/1609