Vulnerabilities > CVE-2006-1553 - SQL Injection vulnerability in Tachyon Vsns Lemon 3.2.0

047910
CVSS 5.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
high complexity
tachyon

Summary

SQL injection vulnerability in functions/final_functions.php in VSNS Lemon 3.2.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter. Successful exploitation requires that the "magic_quotes_gpc" parameter is disabled.

Vulnerable Configurations

Part Description Count
Application
Tachyon
1