Vulnerabilities > CVE-2006-3271 - SQL Injection vulnerability in Softbiz Dating Script 1.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Multiple SQL injection vulnerabilities in Softbiz Dating 1.0 allow remote attackers to execute SQL commands via the (1) country and (2) sort_by parameters in (a) search_results.php; (3) browse parameter in (b) featured_photos.php; (4) cid parameter in (c) products.php, (d) index.php, and (e) news_desc.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description SoftBiz Dating Script 1.0 featured_photos.php browse Parameter SQL Injection. CVE-2006-3271. Webapps exploit for php platform id EDB-ID:28093 last seen 2016-02-03 modified 2006-06-22 published 2006-06-22 reporter EllipSiS Security source https://www.exploit-db.com/download/28093/ title SoftBiz Dating Script 1.0 featured_photos.php browse Parameter SQL Injection description SoftBiz Dating Script 1.0 products.php cid Parameter SQL Injection. CVE-2006-3271. Webapps exploit for php platform id EDB-ID:28094 last seen 2016-02-03 modified 2006-06-22 published 2006-06-22 reporter EllipSiS Security source https://www.exploit-db.com/download/28094/ title SoftBiz Dating Script 1.0 products.php cid Parameter SQL Injection description SoftBiz Dating Script 1.0 news_desc.php id Parameter SQL Injection. CVE-2006-3271. Webapps exploit for php platform id EDB-ID:28096 last seen 2016-02-03 modified 2006-06-22 published 2006-06-22 reporter EllipSiS Security source https://www.exploit-db.com/download/28096/ title SoftBiz Dating Script 1.0 news_desc.php id Parameter SQL Injection description SoftBizScripts Dating Script SQL Injection Vunerability. CVE-2006-3271. Webapps exploit for php platform id EDB-ID:12438 last seen 2016-02-01 modified 2010-04-28 published 2010-04-28 reporter 41.w4r10r source https://www.exploit-db.com/download/12438/ title SoftBizScripts Dating Script SQL Injection Vunerability description SoftBiz Dating Script 1.0 index.php cid Parameter SQL Injection. CVE-2006-3271. Webapps exploit for php platform id EDB-ID:28095 last seen 2016-02-03 modified 2006-06-22 published 2006-06-22 reporter EllipSiS Security source https://www.exploit-db.com/download/28095/ title SoftBiz Dating Script 1.0 index.php cid Parameter SQL Injection