7.5
CVSSv2

CVE-2006-3963

Published: 01/08/2006 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Banex PHP MySQL Banner Exchange 2.21 allow remote malicious users to execute arbitrary SQL commands via the (1) site_name parameter to (a) signup.php, and the (2) id, (3) deleteuserbanner, (4) viewmem, (5) viewmemunb, (6) viewunmem,or (7) deleteuser parameters to (b) admin.php.

Vulnerable Product Search on Vulmon Subscribe to Product

banex banex 2.21

Exploits

source: wwwsecurityfocuscom/bid/19240/info PHP MySQL Banner Exchange is prone to multiple SQL-injection vulnerabilities and a remote file-include vulnerability because it fails to properly sanitize user-supplied input An attacker can exploit the SQL-injection vulnerabilities to compromise the application, access or modify data, or ex ...
source: wwwsecurityfocuscom/bid/19240/info PHP MySQL Banner Exchange is prone to multiple SQL-injection vulnerabilities and a remote file-include vulnerability because it fails to properly sanitize user-supplied input An attacker can exploit the SQL-injection vulnerabilities to compromise the application, access or modify data, or expl ...