Vulnerabilities > CVE-2006-2911 - SQL Injection vulnerability in CMS MUNDO Control Panel

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
hotwebscripts

Summary

SQL injection vulnerability in controlpanel/index.php in CMS Mundo before 1.0 build 008 allows remote attackers to execute arbitrary SQL commands via the username parameter.

Vulnerable Configurations

Part Description Count
Application
Hotwebscripts
2