Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2006-1828


Vulnerability Score 5.1 5.1
CVE Id CVE-2006-1828
Last Modified 07 Mar 2011 09:34:22
Published 19 Apr 2006 12:06:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity HIGH
Authentication NONE



SQL injection vulnerability in php121language.php in PHP121 1.4 allows remote attackers to execute arbitrary SQL commands and execute arbitrary code via the sess_username variable, as set by the php121un HTTP COOKIE parameter, which is used in multiple files including php121login.php. NOTE: the code execution occurs because the SQL query results are used in an include statement.

Vulnerable Systems


  • Php121 Instant Messenger 1.4


VUPEN - ADV-2006-1349

SECUNIA - 19643

MILW0RM - 1666

XF - php121-php121login-sql-injection(25785)

BID - 17509

SECTRACK - 1015936


Last Updated: 27 May 2016 10:42:14