Vulnerabilities > CVE-2006-2339 - SQL Injection vulnerability in Evo-Dev Evotopsites and Evotopsites PRO

047910
CVSS 6.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
evo-dev
exploit available

Summary

SQL injection vulnerability in index.php in evoTopsites 2.x and evoTopsites Pro 2.x allows remote attackers to execute arbitrary SQL commands via the (1) cat_id and (2) id parameters.

Vulnerable Configurations

Part Description Count
Application
Evo-Dev
2

Exploit-Db

descriptionEvoTopsite 2.0 Index.PHP Multiple SQL Injection Vulnerabilities. CVE-2006-2339 . Webapps exploit for php platform
idEDB-ID:27837
last seen2016-02-03
modified2006-05-08
published2006-05-08
reporterHamid Ebadi
sourcehttps://www.exploit-db.com/download/27837/
titleEvoTopsite 2.0 Index.PHP Multiple SQL Injection Vulnerabilities