PT-2006-2489 · Php · Php Ticket

Undefined1

·

Published

2006-03-29

·

Updated

2017-10-19

·

CVE-2006-1481

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: PHP Ticket version 0.71
Description: The issue allows remote authenticated users to execute arbitrary SQL commands and obtain sensitive information, such as usernames and passwords, via the frm search in parameter in the search.php file.
Recommendations: For PHP Ticket version 0.71, consider restricting access to the search.php file or disabling the frm search in parameter to minimize the risk of exploitation until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1481

Affected Products

Php Ticket