PT-2006-1902 · Scriptme · Scriptme Sme Gb Host

Aliaksandr Hartsuyeu

·

Published

2006-02-23

·

Updated

2018-10-18

·

CVE-2006-0856

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Scriptme SmE GB Host version 1.21
Description The issue allows remote attackers to execute arbitrary SQL commands and bypass authentication. This is achieved via the Username parameter in the "login.php" file.
Recommendations For version 1.21, consider restricting access to the login.php file until a patch is available, and avoid using the Username parameter in a way that could allow SQL injection attacks.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-0856

Affected Products

Scriptme Sme Gb Host