Vulnerabilities > CVE-2006-2972 - SQL Injection vulnerability in Vice Stats VS_Resource.PHP

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
arantius

Summary

SQL injection vulnerability in vs_resource.php in Arantius Vice Stats 0.5b and 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

Vulnerable Configurations

Part Description Count
Application
Arantius
2