PoC Index

CVE-2006-2268

HIGH 7.5EPSS 2.0%

SQL injection vulnerability in FlexCustomer 0.0.4 and earlier allows remote attackers to bypass authentication and execute arbitrary SQL commands via the admin and ordinary user interface, probably involving the (1) checkuser and (2) checkpass parameters to (a) admin/index.php, and (3) username and (4) password parameters to (b) index.php. NOTE: it was later reported that 0.0.6 is also affected.

CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
2.02% chance of exploitation in the next 30 days, 80th percentile
Published
2006-05-09
Updated
2024-08-07

Proof-of-concept exploits (1)

References

Related