Vulnerabilities > CVE-2006-3012 - SQL Injection vulnerability in phpBannerExchange

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
eschew-net

Summary

SQL injection vulnerability in phpBannerExchange before 2.0 Update 6 allows remote attackers to execute arbitrary SQL commands via the (1) login parameter in (a) client/stats.php and (b) admin/stats.php, or the (2) pass parameter in client/stats.php.

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/47616/rt-sa-2006-004.txt
idPACKETSTORM:47616
last seen2016-12-05
published2006-06-25
reporterRedTeam Pentesting
sourcehttps://packetstormsecurity.com/files/47616/rt-sa-2006-004.txt.html
titlert-sa-2006-004.txt