SQL Injection Vulnerability in eNdonesia Product by eNdonesia
CVE-2006-6873

Currently unrated

Key Information:

Vendor

Endonesia

Status
Vendor
CVE Published:
31 December 2006

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2006-6873?

Multiple SQL injection vulnerabilities in mod.php of eNdonesia 8.4 can be exploited by remote attackers to execute arbitrary SQL commands. The vulnerabilities are associated with the 'did' parameter during the viewdisk operation in the diskusi mod, and the 'cid' parameter during the viewlink and viewcat operations in the katalog and diskusi mods, respectively. This flaw creates significant security risks, enabling malicious actors to manipulate database queries and potentially compromise sensitive data.

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • Vulnerability Reserved

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

.