Vulnerabilities > CVE-2006-2552 - SQL Injection vulnerability in Jemscripts Downloadcontrol 1.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
NONE Availability impact
NONE Summary
Jemscripts DownloadControl 1.0 allows remote attackers to obtain sensitive information via an invalid dcid parameter to dc.php, which leaks the pathname in an error message. NOTE: this was originally claimed to be SQL injection, but it is probably resultant from another issue in functions.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | JemWeb DownloadControl 1.0 DC.PHP SQL Injection Vulnerability. CVE-2006-2552. Webapps exploit for php platform |
id | EDB-ID:27899 |
last seen | 2016-02-03 |
modified | 2006-05-19 |
published | 2006-05-19 |
reporter | Luny |
source | https://www.exploit-db.com/download/27899/ |
title | JemWeb DownloadControl 1.0 DC.PHP SQL Injection Vulnerability |