CVE-2006-5829: SQL Injection
Multiple SQL injection vulnerabilities in All In One Control Panel (AIOCP) 1.3.007 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) choosedlanguage parameter to (a) cpdpage.php, (b) cpnews.php, (c) cpforumview.php, (d) cpedituser.php, (e) cpnewsletter.php, (f) cplinks.php, (g) cpcontactus.php, (h) cplogin.php, and (i) cpcodicefiscale.php in public/code/; (2) newscategory parameter to public/code/cpnews.php; (3) nlmsgnlcatid parameter to public/code/cpnewsletter.php; (4) linkscategory parameter to public/code/cplinks.php; (5) productcategoryid parameter to public/code/cpshowecproducts.php; (6) orderfield parameter to public/code/cpshowecproducts.php; (7) firstrow parameter to public/code/cpusersonline.php; and (8) orderdir parameter to public/code/cplinkssearch.php.
Affected Software
Event History
Frequently Asked Questions
Which AIOCP installations are affected?
AIOCP version 1.3.007 and earlier is affected. The provided data does not identify a fixed version.
Does exploitation require an authenticated account?
No. The vulnerability is described as exploitable by remote attackers, and the supplied vector specifies no authentication requirement.