7.5
CVSSv2

CVE-2006-0123

Published: 09/01/2006 Updated: 19/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in ADN Forum 1.0b allow remote malicious users to execute arbitrary SQL commands via the (1) fid parameter in index.php and (2) pagid parameter in verpag.php, and possibly other vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

adn forum adn forum 1.0

adn forum adn forum 1.0b

Exploits

#!/usr/bin/perl # -------------------------------------------------- # ADN Forum <= 10b Blind SQL Injection Exploit # Discovered By: StAkeR - StAkeR[at]hotmail[dot]it # Discovered On: 01/10/2008 # Download: sourceforgenet/projects/adnforum/ # -------------------------------------------------- # Usage: perl exploitpl localhost # ...