PT-2006-2337 · Unknown · Skull-Splitter Php Downloadcounter For Wallpapers

·

CVE-2006-1328

·

Published

2006-03-21

·

Updated

2018-10-18

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Skull-Splitter PHP Downloadcounter for Wallpapers version 1.0
Description The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the count fieldname, url fieldname, or url parameters.
Recommendations For Skull-Splitter PHP Downloadcounter for Wallpapers version 1.0, consider restricting access to the count.php file until a patch is available. As a temporary workaround, avoid using the count fieldname, url fieldname, and url parameters in the affected API endpoint.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1328

Affected Products

Skull-Splitter Php Downloadcounter For Wallpapers