Title : Chirpy! Unspecified Parameter Handling Remote SQL Injection Vulnerability VUPEN ID : VUPEN/ADV-2006-1777 CVE ID : CVE-2006-2266
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-05-11
Technical Description
A vulnerability has been identified in Chirpy!, which could be exploited by remote attackers to execute arbitrary SQL commands. Thi flaw is due to an input validation error in an unspecified script that does not validate certain parameters before being used in SQL statements, which could be exploited by malicious people to conduct SQL injection attacks.