SecurityAlert : 1266 CVE : CVE-2006-3770 SecurityRisk : Medium (About) Remote Exploit : Yes Local Exploit : No Exploit Available : No Credit : David "Aesthetico" Vieira-Kurz Published : 26.07.2006
phpFaber TopSites is a feature-packed, reliable and secure Top List for
webmasters who want to increase traffic to their websites.
It is fully customizable and doesn't require any programming skills! You
can create your forms just in 3 clicks!
Vulnerability:
----------------------------------------------
Input passed directly to the "i_cat" and "method" parameter in "index.php"
is not properly sanitised before being used in a SQL query.
This can be exploited to manipulate SQL queries by injecting arbitrary SQL
code.
Solution:
----------------------------------------------
Edit the source code to ensure that input is properly sanitised.
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.