phpNewsManager Multiple SQL Injections
eVuln ID: EV0110
CVE: CVE-2006-1560
Vendor: SkinTech Group
Vendor's Web Site: 
Software: phpNewsManager
Versions: 1.48
Critical Level: Moderate
Type: SQL Injection
Class: Remote
Status: Unpatched. No reply from developer(s)
PoC/Exploit: Not Available
Solution: Not Available
Discovered by: Aliaksandr Hartsuyeu (

All user-defined variables are not properly sanitized before being used in SQL queries. This can be used to bypass authentication or make any SQL query by injecting arbitrary SQL code.

Vulnerable scripts:

Waiting for developer(s) reply.
If there is no reply exploitation code will be published in 10 days 

No Patch available.

Aliaksandr Hartsuyeu - Penetration Testing Services 

