Vulnerabilities > CVE-2006-5676 - SQL-Injection vulnerability in PhpLeague

047910
CVSS 6.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
uni-vert
exploit available

Summary

SQL injection vulnerability in consult/classement.php in Uni-Vert PhpLeague 0.82 and earlier allows remote attackers to execute arbitrary SQL commands via the champ parameter.

Vulnerable Configurations

Part Description Count
Application
Uni-Vert
1

Exploit-Db

descriptionPhp League 0.82 (classement.php) Remote SQL Injection Exploit. CVE-2006-5676. Webapps exploit for asp platform
fileexploits/asp/webapps/2661.asp
idEDB-ID:2661
last seen2016-01-31
modified2006-10-27
platformasp
port
published2006-10-27
reporterajann
sourcehttps://www.exploit-db.com/download/2661/
titlePhp League 0.82 classement.php Remote SQL Injection Exploit
typewebapps