Vulnerabilities > CVE-2006-1838 - SQL Injection and Authentication Bypass vulnerability in Clanscripte.Net Fuju News 1.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
clanscripte-net
exploit available

Summary

edit_kategorie.php in Fuju News 1.0 allows remote attackers to bypass authentication by setting the authorized cookie.

Vulnerable Configurations

Part Description Count
Application
Clanscripte.Net
1

Exploit-Db

descriptionFuju News 1.0 Authentication Bypass / Remote SQL Injection Exploit. CVE-2006-1837,CVE-2006-1838. Webapps exploit for php platform
fileexploits/php/webapps/1682.php
idEDB-ID:1682
last seen2016-01-31
modified2006-04-16
platformphp
port
published2006-04-16
reportersnatcher
sourcehttps://www.exploit-db.com/download/1682/
titleFuju News 1.0 - Authentication Bypass / Remote SQL Injection Exploit
typewebapps