This application requires Javascript for optimal performance.

SaPHPLesson.Add.And.Show.PHP.SQL.Injection

Release Date

Nov 03, 2011

Severity

high

Impact

System Compromise: Arbitrary SQL command execution.

Description

This indicates an attempt to exploit a SQL Injection vulnerability in SaphpLesson.

The vulnerability is a result of the application's failure to check user input before using it in an SQL query. It may allow a remote attacker to send a crafted query to execute SQL commands on a vulnerable server.

Affected Products

Arabless.com SaphpLesson 2.0

Recommended Actions

Currently, we are not aware of any vendor supplied patches for this issue.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2006-2835

Reference: VID-29661