Vulnerabilities > CVE-2006-4876 - Input Validation vulnerability in Jupiter CMS

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
jupiter-cms
exploit available

Summary

Multiple SQL injection vulnerabilities in Jupiter CMS allow remote attackers to execute arbitrary SQL commands via (1) the user name during login, or the (2) key or (3) fpwusername parameters in modules/register.

Vulnerable Configurations

Part Description Count
Application
Jupiter_Cms
1

Exploit-Db

descriptionJupiter CMS 1.1.4/1.1.5 modules/register Multiple Parameter SQL Injection. CVE-2006-4876. Webapps exploit for php platform
idEDB-ID:28586
last seen2016-02-03
modified2006-09-15
published2006-09-15
reporterHACKERS PAL
sourcehttps://www.exploit-db.com/download/28586/
titleJupiter CMS 1.1.4/1.1.5 modules/register Multiple Parameter SQL Injection