Vulnerabilities > CVE-2006-1572 - SQL Injection vulnerability in O2PHP Oxygen Post.PHP

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
o2php-com
exploit available

Summary

SQL injection vulnerability in post.php in Oxygen 1.1.3 allows remote attackers to execute arbitrary SQL commands via the fid parameter in a newthread action.

Exploit-Db

descriptionO2PHP Oxygen 1.0/1.1 Post.PHP SQL Injection Vulnerability. CVE-2006-1572. Webapps exploit for php platform
idEDB-ID:27535
last seen2016-02-03
modified2006-03-30
published2006-03-30
reporterMorocco Security Team
sourcehttps://www.exploit-db.com/download/27535/
titleO2PHP Oxygen 1.0/1.1 Post.PHP SQL Injection Vulnerability