Vulnerabilities > CVE-2006-1571 - SQL Injection vulnerability in R2Xdesign Qlitenews 20050701

047910
CVSS 5.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
high complexity
r2xdesign

Summary

Multiple SQL injection vulnerabilities in loginprocess.php in qliteNews 2005.07.01 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters. Successful exploitation requires "magic_quotes_gpc" to be disabled.

Vulnerable Configurations

Part Description Count
Application
R2Xdesign
1