Vulnerabilities > CVE-2006-1495 - SQL Injection vulnerability in PhpCollab Sendpassword.PHP
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
SQL injection vulnerability in general/sendpassword.php in (1) PHPCollab 2.4 and 2.5.rc3, and (2) NetOffice 2.5.3-pl1 and 2.6.0b2 allows remote attackers to execute arbitrary SQL commands via the loginForm parameter in the "forgotten password" option.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 | |
Application | 2 |
Exploit-Db
description | PHPCollab 2.x / NetOffice 2.x (sendpassword.php) SQL Injection Exploit. CVE-2006-1495. Webapps exploit for php platform |
file | exploits/php/webapps/1617.php |
id | EDB-ID:1617 |
last seen | 2016-01-31 |
modified | 2006-03-28 |
platform | php |
port | |
published | 2006-03-28 |
reporter | rgod |
source | https://www.exploit-db.com/download/1617/ |
title | PHPCollab 2.x / NetOffice 2.x - sendpassword.php SQL Injection Exploit |
type | webapps |
Nessus
NASL family | Gentoo Local Security Checks |
NASL id | GENTOO_GLSA-200812-20.NASL |
description | The remote host is affected by the vulnerability described in GLSA-200812-20 (phpCollab: Multiple vulnerabilities) Multiple vulnerabilities have been found in phpCollab: rgod reported that data sent to general/sendpassword.php via the loginForm parameter is not properly sanitized before being used in an SQL statement (CVE-2006-1495). Christian Hoffmann of Gentoo Security discovered multiple vulnerabilities where input is insufficiently sanitized before being used in a SQL statement, for instance in general/login.php via the loginForm parameter. (CVE-2008-4303). Christian Hoffmann also found out that the variable $SSL_CLIENT_CERT in general/login.php is not properly sanitized before being used in a shell command. (CVE-2008-4304). User-supplied data to installation/setup.php is not checked before being written to include/settings.php which is executed later. This issue was reported by Christian Hoffmann as well (CVE-2008-4305). Impact : These vulnerabilities enable remote attackers to execute arbitrary SQL statements and PHP code. NOTE: Some of the SQL injection vulnerabilities require the php.ini option |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 35257 |
published | 2008-12-22 |
reporter | This script is Copyright (C) 2008-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/35257 |
title | GLSA-200812-20 : phpCollab: Multiple vulnerabilities |
code |
|
References
- http://downloads.securityfocus.com/vulnerabilities/exploits/PHPCollab_NetOffice_SQLINJ.php
- http://secunia.com/advisories/19449
- http://secunia.com/advisories/19452
- http://secunia.com/advisories/33258
- http://security.gentoo.org/glsa/glsa-200812-20.xml
- http://www.osvdb.org/24226
- http://www.osvdb.org/24230
- http://www.securityfocus.com/bid/17283
- http://www.securityfocus.com/bid/17286
- http://www.vupen.com/english/advisories/2006/1141
- http://www.vupen.com/english/advisories/2006/1142
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25503
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25505
- https://www.exploit-db.com/exploits/1617