Vulnerabilities > CVE-2006-4072 - SQL-Injection vulnerability in Club-Nuke 2.0Lcid2048

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
club-nuke
exploit available

Summary

Multiple SQL injection vulnerabilities in Club-Nuke [XP] 2.0 LCID 2048 allow remote attackers to execute arbitrary SQL commands via the (1) haber_id parameter to haber_detay.asp, and allow remote authenticated users to execute arbitrary SQL commands via the (2) menu_id parameter to menu.asp. User Logins must be enabled by Admin to exploit this vulnerability.

Vulnerable Configurations

Part Description Count
Application
Club-Nuke
1

Exploit-Db

descriptionCLUB-Nuke [XP] 2.0 LCID 2048 (Turkish Version) SQL Injection. CVE-2006-4072. Webapps exploit for asp platform
fileexploits/asp/webapps/2150.txt
idEDB-ID:2150
last seen2016-01-31
modified2006-08-08
platformasp
port
published2006-08-08
reporterASIANEAGLE
sourcehttps://www.exploit-db.com/download/2150/
titleCLUB-Nuke XP 2.0 LCID 2048 Turkish Version - SQL Injection
typewebapps