Vulnerabilities > CVE-2006-7005 - SQL-Injection vulnerability in PSY Auction

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
php-script-tools
exploit available

Summary

SQL injection vulnerability in item.php in PSY Auction allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Vulnerable Configurations

Part Description Count
Application
Php_Script_Tools
1

Exploit-Db

descriptionPHP Script Tools PSY Auction 0 item.php id Parameter SQL Injection. CVE-2006-7005. Webapps exploit for php platform
idEDB-ID:27869
last seen2016-02-03
modified2006-05-15
published2006-05-15
reporterLuny
sourcehttps://www.exploit-db.com/download/27869/
titlePHP Script Tools PSY Auction - item.php id Parameter SQL Injection