Vulnerabilities > CVE-2006-1817 - Input Validation vulnerability in the WAR Forge Warforge.News 1.0

047910
CVSS 2.6 - LOW
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
high complexity
the-war-forge

Summary

SQL injection vulnerability in authcheck.php in warforge.NEWS 1.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the (1) authusername and possibly the (2) authpassword cookie.

Vulnerable Configurations

Part Description Count
Application
The_War_Forge
1