Vulnerabilities > CVE-2006-4114 - SQL Injection vulnerability in PHPMyRing IDSITE
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
SQL injection vulnerability in view_com.php in Nicolas Grandjean PHPMyRing 4.2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the idsite parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | PHPMyRing <= 4.2.0 (view_com.php) Remote SQL Injection Exploit. CVE-2006-4114. Webapps exploit for php platform |
file | exploits/php/webapps/2159.pl |
id | EDB-ID:2159 |
last seen | 2016-01-31 |
modified | 2006-08-09 |
platform | php |
port | 80 |
published | 2006-08-09 |
reporter | simo64 |
source | https://www.exploit-db.com/download/2159/ |
title | PHPMyRing <= 4.2.0 view_com.php Remote SQL Injection Exploit |
type | webapps |
References
- http://archives.neohapsis.com/archives/bugtraq/2006-08/0184.html
- http://secunia.com/advisories/21451
- http://securitytracker.com/id?1016686
- http://www.morx.org/ring.txt
- http://www.osvdb.org/27881
- http://www.securityfocus.com/archive/1/442808/100/100/threaded
- http://www.securityfocus.com/bid/19456
- http://www.vupen.com/english/advisories/2006/3238
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28318
- https://www.exploit-db.com/exploits/2159