Описание
Multiple SQL injection vulnerabilities in Enthrallweb eClassifieds allow remote attackers to execute arbitrary SQL commands via the (1) AD_ID, (2) cat_id, (3) sub_id, and (4) ad_id parameters to (a) ad.asp, the (5) cid parameter to (b) dircat.asp, and the (6) sid parameter to (c) dirSub.asp.
Multiple SQL injection vulnerabilities in Enthrallweb eClassifieds allow remote attackers to execute arbitrary SQL commands via the (1) AD_ID, (2) cat_id, (3) sub_id, and (4) ad_id parameters to (a) ad.asp, the (5) cid parameter to (b) dircat.asp, and the (6) sid parameter to (c) dirSub.asp.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2006-6208
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30423
- http://s-a-p.ca/index.php?page=OurAdvisories&id=46
- http://secunia.com/advisories/23050
- http://securityreason.com/securityalert/1943
- http://www.securityfocus.com/archive/1/452102/100/100/threaded
- http://www.securityfocus.com/bid/21192
- http://www.vupen.com/english/advisories/2006/4642
EPSS
CVE ID
Связанные уязвимости
Multiple SQL injection vulnerabilities in Enthrallweb eClassifieds allow remote attackers to execute arbitrary SQL commands via the (1) AD_ID, (2) cat_id, (3) sub_id, and (4) ad_id parameters to (a) ad.asp, the (5) cid parameter to (b) dircat.asp, and the (6) sid parameter to (c) dirSub.asp.
EPSS