PT-2006-2337 · Unknown · Skull-Splitter Php Downloadcounter For Wallpapers

Aliaksandr Hartsuyeu

·

Published

2006-03-21

·

Updated

2018-10-18

·

CVE-2006-1328

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Skull-Splitter PHP Downloadcounter for Wallpapers version 1.0
Description The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the count fieldname, url fieldname, or url parameters.
Recommendations For Skull-Splitter PHP Downloadcounter for Wallpapers version 1.0, consider restricting access to the count.php file until a patch is available. As a temporary workaround, avoid using the count fieldname, url fieldname, and url parameters in the affected API endpoint.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1328

Affected Products

Skull-Splitter Php Downloadcounter For Wallpapers