Vulnerabilities > CVE-2006-1773 - SQL Injection vulnerability in PHPKIT Include.PHP

047910
CVSS 6.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
phpkit
nessus
exploit available

Summary

SQL injection vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to execute arbitrary SQL commands via the contentid parameter, possibly involving content/news.php.

Vulnerable Configurations

Part Description Count
Application
Phpkit
1

Exploit-Db

descriptionPHPKIT 1.6.1 R2 Include.PHP SQL Injection Vulnerability. CVE-2006-1773. Webapps exploit for php platform
idEDB-ID:27624
last seen2016-02-03
modified2006-04-11
published2006-04-11
reporterHamid Ebadi
sourcehttps://www.exploit-db.com/download/27624/
titlePHPKIT 1.6.1 R2 Include.PHP SQL Injection Vulnerability

Nessus

NASL familyCGI abuses
NASL idPHPKIT_MULTIPLE_FLAWS.NASL
descriptionThe remote host is running PHP-Kit, an open source content management system written in PHP. The remote version of this software is vulnerable to multiple remote and local code execution, SQL injection and cross-site scripting flaws.
last seen2020-06-01
modified2020-06-02
plugin id15784
published2004-11-22
reporterThis script is Copyright (C) 2004-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/15784
titlePHP-Kit <= 1.6.1 RC2 Multiple Vulnerabilities