PT-2006-2764 · Php · Phpkit

Published

2006-04-13

·

Updated

2017-07-20

·

CVE-2006-1773

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions PHPKIT versions 1.6.1 Release 2 and earlier
Description The issue allows remote attackers to execute arbitrary SQL commands, possibly involving content/news.php, via the contentid parameter in include.php.
Recommendations For PHPKIT versions 1.6.1 Release 2 and earlier, avoid using the contentid parameter in the affected include.php file until a fix is available. Consider restricting access to include.php to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1773

Affected Products

Phpkit