7.5

CVE-2006-6074

Exploit
Multiple SQL injection vulnerabilities in Enthrallweb eShopping Cart allow remote attackers to execute arbitrary SQL commands via (1) the ProductID parameter in (a) reviews.asp, or the (2) cat_id or (3) sub_id parameter in (b) subProducts.asp.  NOTE: the productdetail.asp vector is already covered by another identifier.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.4% 0.69
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://s-a-p.ca/index.php?page=OurAdvisories&id=21
Exploit
URL Repurposed
http://secunia.com/advisories/22955
Vendor Advisory
http://securityreason.com/securityalert/1906
http://www.securityfocus.com/archive/1/451840/100/0/threaded
http://www.securityfocus.com/bid/21151
http://www.vupen.com/english/advisories/2006/4578