7.5
CVSSv2

CVE-2006-6880

Published: 31/12/2006 Updated: 19/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in code/guestadd.php in PHP-Update 2.7 and previous versions allow remote malicious users to execute arbitrary SQL commands via the (1) newmessage, (2) newname, (3) newwebsite, or (4) newemail parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

php-update php-update

Exploits

<?php print_r(' --------------------------------------------------------------------------- PHP-Update <= 27 str_replace() sql injection / privilege escalation / / cmd exec ii by rgod dork: "Powered by PHP-Update" -site:wwwphp-updatecouk -ihackstuff -exploit mail: retrog at alice dot it site: retrogodaltervistaorg -------- ...