PT-2006-5428 · Php League · Uni-Vert Phpleague

Published

2006-09-08

·

Updated

2011-03-08

·

CVE-2006-4643

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Uni-Vert PhpLeague versions 0.82 and earlier
Description A SQL injection issue allows remote attackers to execute arbitrary SQL commands via the id joueur parameter in the consult/joueurs.php file.
Recommendations For Uni-Vert PhpLeague versions 0.82 and earlier, consider restricting access to the consult/joueurs.php file until a patch is available, and avoid using the id joueur parameter in this context to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-4643

Affected Products

Uni-Vert Phpleague