Vulnerabilities > CVE-2006-3959 - SQL Injection vulnerability in X-Scripts X-Statistics 1.10

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
x-scripts
exploit available

Summary

SQL injection vulnerability in protect.php in X-Scripts X-Protection 1.10, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameter.

Vulnerable Configurations

Part Description Count
Application
X-Scripts
1

Exploit-Db

descriptionX-Scripts X-Protection 1.10 Protect.PHP SQL Injection Vulnerability. CVE-2006-3959. Webapps exploit for php platform
idEDB-ID:28303
last seen2016-02-03
modified2006-07-29
published2006-07-29
reporterSirDarckCat
sourcehttps://www.exploit-db.com/download/28303/
titleX-Scripts X-Protection 1.10 Protect.PHP SQL Injection Vulnerability