CVE-2006-6074
Last modified
CVE-2006-6074 is a vulnerability of currently unknown severity. Multiple SQL injection vulnerabilities in Enthrallweb eShopping Cart allow remote attackers to execute arbitrary SQL commands via (1) the ProductID parameter in (a) reviews.asp, or the (2) cat_id or (3) sub_id parameter in (b) subProducts.asp. NOTE: the productdetail.asp vector is already covered by another identifier.. EPSS estimates a 1.40% chance of exploitation in the next 30 days.
Description
Multiple SQL injection vulnerabilities in Enthrallweb eShopping Cart allow remote attackers to execute arbitrary SQL commands via (1) the ProductID parameter in (a) reviews.asp, or the (2) cat_id or (3) sub_id parameter in (b) subProducts.asp. NOTE: the productdetail.asp vector is already covered by another identifier.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Enthrallweb | Eshopping Cart | All versions |
References
- http://s-a-p.ca/index.php?page=OurAdvisories&id=21Exploit, URL Repurposed
- http://secunia.com/advisories/22955Vendor Advisory
- http://s-a-p.ca/index.php?page=OurAdvisories&id=21Exploit, URL Repurposed
- http://secunia.com/advisories/22955Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-6074?
How severe is CVE-2006-6074?
How do I fix CVE-2006-6074?
Are you affected by CVE-2006-6074?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
