Vulnerabilities > CVE-2006-1710 - SQL Injection vulnerability in Design Nation Dnguestbook 2.0

047910
CVSS 7.6 - HIGH
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
high complexity
design-nation
exploit available

Summary

SQL injection vulnerability in admin.php in Design Nation DNGuestbook 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) email and (2) id parameters. Successful exploitation requires that "magic_quotes_gpc" is disabled.

Vulnerable Configurations

Part Description Count
Application
Design_Nation
1

Exploit-Db

descriptiondnGuestbook <= 2.0 Remote SQL Injection Vulnerabilities. CVE-2006-1710. Webapps exploit for php platform
fileexploits/php/webapps/1653.txt
idEDB-ID:1653
last seen2016-01-31
modified2006-04-09
platformphp
port
published2006-04-09
reportersnatcher
sourcehttps://www.exploit-db.com/download/1653/
titlednGuestbook <= 2.0 - Remote SQL Injection Vulnerabilities
typewebapps