Vulnerabilities > CVE-2006-6339 - SQL Injection vulnerability in Devilz Clanportal Devilz Clanportal 1.3.6

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
devilz-clanportal
exploit available

Summary

SQL injection vulnerability in sites/index.php in deV!L`z Clanportal (DZCP) before 1.3.6.1 allows remote attackers to execute arbitrary SQL commands via the show element in a GET request.

Vulnerable Configurations

Part Description Count
Application
Devilz_Clanportal
1

Exploit-Db

descriptiondeV!Lz Clanportal 1.3.6 Show Parameter SQL Injection Vulnerability. CVE-2006-6339. Webapps exploit for php platform
idEDB-ID:29207
last seen2016-02-03
modified2006-12-01
published2006-12-01
reporterTim Weber
sourcehttps://www.exploit-db.com/download/29207/
titledeV!Lz Clanportal 1.3.6 Show Parameter SQL Injection Vulnerability