CVE-2006-0444
Last modified
CVE-2006-0444 is a vulnerability of currently unknown severity. SQL injection vulnerability in index.php in Phpclanwebsite (aka PCW) 1.23.1 allows remote attackers to execute arbitrary SQL commands via the (1) par parameter in the post function on the forum page and possibly the (2) poll_id parameter on the poll page. NOTE: the poll_id vector can also allow resultant cross-site scripting (XSS) from an unquoted error message for invalid SQL syntax.. EPSS estimates a 2.98% chance of exploitation in the next 30 days.
Description
SQL injection vulnerability in index.php in Phpclanwebsite (aka PCW) 1.23.1 allows remote attackers to execute arbitrary SQL commands via the (1) par parameter in the post function on the forum page and possibly the (2) poll_id parameter on the poll page. NOTE: the poll_id vector can also allow resultant cross-site scripting (XSS) from an unquoted error message for invalid SQL syntax.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Phpclanwebsite | Phpclanwebsite | 1.23.1 |
References
- http://secunia.com/advisories/18597Patch, Vendor Advisory
- http://www.h4cky0u.org/advisories/HYSA-2006-002-phpclan.txtExploit, Vendor Advisory
- http://secunia.com/advisories/18597Patch, Vendor Advisory
- http://www.h4cky0u.org/advisories/HYSA-2006-002-phpclan.txtExploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-0444?
How severe is CVE-2006-0444?
How do I fix CVE-2006-0444?
Are you affected by CVE-2006-0444?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
