CVE-2006-1828

SQL injection vulnerability in php121language.php in PHP121 1.4 allows remote attackers to execute arbitrary SQL commands and execute arbitrary code via the sess_username variable, as set by the php121un HTTP COOKIE parameter, which is used in multiple files including php121login.php. NOTE: the code execution occurs because the SQL query results are used in an include statement.
Configurations

Configuration 1 (hide)

cpe:2.3:a:php121:php121_instant_messenger:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2006-04-19 16:06

Updated : 2024-02-04 16:52


NVD link : CVE-2006-1828

Mitre link : CVE-2006-1828

CVE.ORG link : CVE-2006-1828


JSON object : View

Products Affected

php121

  • php121_instant_messenger