Vulnerabilities > CVE-2006-4585 - SQL Injection And Authentication Bypass vulnerability in TR Forum TR Forum 2.0

047910
CVSS 9.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
tr-forum
critical
exploit available

Summary

SQL injection vulnerability in admin/editer.php in Tr Forum 2.0 allows remote authenticated users to execute arbitrary SQL commands via the id2 parameter. NOTE: this can be leveraged with other Tr Forum vulnerabilities to allow unauthenticated attackers to gain privileges.

Vulnerable Configurations

Part Description Count
Application
Tr_Forum
1

Exploit-Db

idEDB-ID:2297