Multiple SQL injection vulnerabilities in X-Changer 0.2 allow remote attackers to execute arbitrary SQL commands via the (1) from and (2) into parameters in a calculate action, and the (3) id parameter in an edit action to index.php.
Loading...
Loading...
Multiple SQL injection vulnerabilities in X-Changer 0.2 allow remote attackers to execute arbitrary SQL commands via the (1) from and (2) into parameters in a calculate action, and the (3) id parameter in an edit action to index.php.
March 31, 2006
April 16, 2026
Working exploit code is in the public domain (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
X-Changer 0.20 - Multiple SQL Injections
Open source ↗See which npm, PyPI, Go, and Maven packages are affected by CVE-2006-1557
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.