Vulnerabilities > CVE-2006-1706 - Unspecified vulnerability in Kansok Communications Shopweezle
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN kansok-communications
exploit available
Summary
Multiple SQL injection vulnerabilities in Shopweezle 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) itemID parameter to (a) login.php and (b) memo.php; and the (2) itemgr, (3) brandID, and (4) album parameters to (c) index.php. NOTE: this issue also produces resultant full path disclosure from invalid SQL queries.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 4 |
Exploit-Db
description ShopWeezle 2.0 memo.php itemID Parameter SQL Injection. CVE-2006-1706. Webapps exploit for php platform id EDB-ID:27614 last seen 2016-02-03 modified 2006-04-10 published 2006-04-10 reporter r0t source https://www.exploit-db.com/download/27614/ title ShopWeezle 2.0 memo.php itemID Parameter SQL Injection description ShopWeezle 2.0 index.php Multiple Parameter SQL Injection. CVE-2006-1706. Webapps exploit for php platform id EDB-ID:27613 last seen 2016-02-03 modified 2006-04-10 published 2006-04-10 reporter r0t source https://www.exploit-db.com/download/27613/ title ShopWeezle 2.0 index.php Multiple Parameter SQL Injection description ShopWeezle 2.0 login.php itemID Parameter SQL Injection. CVE-2006-1706. Webapps exploit for php platform id EDB-ID:27612 last seen 2016-02-03 modified 2006-04-10 published 2006-04-10 reporter r0t source https://www.exploit-db.com/download/27612/ title ShopWeezle 2.0 login.php itemID Parameter SQL Injection
References
- http://pridels0.blogspot.com/2006/04/shopweezle-20-multiple-vuln.html
- http://pridels0.blogspot.com/2006/04/shopweezle-20-multiple-vuln.html
- http://secunia.com/advisories/19593
- http://secunia.com/advisories/19593
- http://www.osvdb.org/24470
- http://www.osvdb.org/24470
- http://www.osvdb.org/24471
- http://www.osvdb.org/24471
- http://www.osvdb.org/24472
- http://www.osvdb.org/24472
- http://www.osvdb.org/24473
- http://www.osvdb.org/24473
- http://www.securityfocus.com/bid/17441
- http://www.securityfocus.com/bid/17441
- http://www.vupen.com/english/advisories/2006/1291
- http://www.vupen.com/english/advisories/2006/1291
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25723
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25723
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25724
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25724