Vulnerabilities > CVE-2006-1353 - SQL Injection vulnerability in Aspportal 3.0.0/3.1.0/3.1.1

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
aspportal
exploit available

Summary

Multiple SQL injection vulnerabilities in ASPPortal 3.1.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the downloadid parameter in download_click.asp and (2) content_ID parameter in news/News_Item.asp; authenticated administrators can also conduct attacks via (3) user_id parameter to users/add_edit_user.asp, (4) bannerid parameter to banner_adds/banner_add_edit.asp, (5) cat_id parameter to categories/add_edit_cat.asp, (6) Content_ID parameter to News/add_edit_news.asp, (7) download_id parameter to downloads/add_edit_download.asp, (8) Poll_ID parameter to poll/add_edit_poll.asp, (9) contactid parameter to contactus/contactus_add_edit.asp, (10) sortby parameter to poll/poll_list.asp, and (11) unspecified inputs to downloads/add_edit_download.asp.

Vulnerable Configurations

Part Description Count
Application
Aspportal
3

Exploit-Db

descriptionASPPortal <= 3.1.1 (downloadid) Remote SQL Injection Exploit. CVE-2006-1353. Webapps exploit for asp platform
fileexploits/asp/webapps/1597.pl
idEDB-ID:1597
last seen2016-01-31
modified2006-03-20
platformasp
port
published2006-03-20
reporternukedx
sourcehttps://www.exploit-db.com/download/1597/
titleASPPortal <= 3.1.1 downloadid Remote SQL Injection Exploit
typewebapps