Vulnerabilities > CVE-2006-6716 - SQL Injection vulnerability in Eric Guillaume Upload Download DE Fichiers 3

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
eric-guillaume
exploit available

Summary

SQL injection vulnerability in administration/administre2.php in Eric GUILLAUME uploader&downloader 3 allows remote attackers to execute arbitrary SQL commands via the id_user parameter.

Vulnerable Configurations

Part Description Count
Application
Eric_Guillaume
1

Exploit-Db

descriptionUploader & Downloader 3.0 (id_user) Remote SQL Injection Vulnerability. CVE-2006-6716. Webapps exploit for php platform
fileexploits/php/webapps/2945.txt
idEDB-ID:2945
last seen2016-01-31
modified2006-12-18
platformphp
port
published2006-12-18
reporterthe master
sourcehttps://www.exploit-db.com/download/2945/
titleUploader & Downloader 3.0 id_user Remote SQL Injection Vulnerability
typewebapps