Vulnerabilities > CVE-2006-3065 - Unspecified vulnerability in Blursoft Blur6Ex 0.3.462
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN blursoft
exploit available
Summary
SQL injection vulnerability in engine/shards/blog.php in blur6ex 0.3.462 allows remote attackers to execute arbitrary SQL commands via the ID parameter in a proc_reply action in the blog shard. NOTE: This is a similar vulnerability to CVE-2006-1763, but the affected code and versions are different.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | blur6ex <= 0.3.462 (ID) Admin Disclosure / Blind SQL Injection Exploit. CVE-2006-3065. Webapps exploit for php platform |
file | exploits/php/webapps/1904.php |
id | EDB-ID:1904 |
last seen | 2016-01-31 |
modified | 2006-06-12 |
platform | php |
port | |
published | 2006-06-12 |
reporter | rgod |
source | https://www.exploit-db.com/download/1904/ |
title | blur6ex <= 0.3.462 ID Admin Disclosure / Blind SQL Injection Exploit |
type | webapps |
References
- http://secunia.com/advisories/20646
- http://secunia.com/advisories/20646
- http://securityreason.com/securityalert/1113
- http://securityreason.com/securityalert/1113
- http://www.securityfocus.com/archive/1/437015/100/0/threaded
- http://www.securityfocus.com/archive/1/437015/100/0/threaded
- http://www.vupen.com/english/advisories/2006/2341
- http://www.vupen.com/english/advisories/2006/2341
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27120
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27120
- https://www.exploit-db.com/exploits/1904
- https://www.exploit-db.com/exploits/1904