Vulnerabilities > CVE-2006-4957 - Unspecified vulnerability in the Myreview System Myreview 1.9.4
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
SQL injection vulnerability in the GetMember function in functions.php in MyReview 1.9.4 allows remote attackers to execute arbitrary SQL commands via the email parameter to Admin.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | MyReview 1.9.4 (email) Remote SQL Injection / Code Execution Exploit. CVE-2006-4957. Webapps exploit for php platform |
file | exploits/php/webapps/2397.py |
id | EDB-ID:2397 |
last seen | 2016-01-31 |
modified | 2006-09-19 |
platform | php |
port | |
published | 2006-09-19 |
reporter | STILPU |
source | https://www.exploit-db.com/download/2397/ |
title | MyReview 1.9.4 email Remote SQL Injection / Code Execution Exploit |
type | webapps |
Nessus
NASL family | CGI abuses |
NASL id | MYREVIEW_EMAIL_SQL_INJECTION.NASL |
description | The remote host is running MyReview, an open source paper submission and review web application. The version of MyReview installed on the remote host fails to properly sanitize input to the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 22413 |
published | 2006-09-19 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/22413 |
title | MyReview Admin.php email Parameter SQL Injection |
code |
|
References
- http://secunia.com/advisories/21991
- http://secunia.com/advisories/21991
- http://www.securityfocus.com/bid/20105
- http://www.securityfocus.com/bid/20105
- http://www.vupen.com/english/advisories/2006/3716
- http://www.vupen.com/english/advisories/2006/3716
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29029
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29029
- https://www.exploit-db.com/exploits/2397
- https://www.exploit-db.com/exploits/2397