Vulnerabilities > CVE-2006-2179 - Input Validation vulnerability in CyberBuild

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
smartwin-technology
exploit available

Summary

Multiple SQL injection vulnerabilities in CyberBuild allow remote attackers to execute arbitrary SQL commands via the (1) SessionID parameter to login.asp or (2) ProductIndex parameter to browse0.htm.

Vulnerable Configurations

Part Description Count
Application
Smartwin_Technology
1

Exploit-Db

  • descriptionCyberBuild 0 browse0.htm ProductIndex Parameter SQL Injection. CVE-2006-2179. Webapps exploit for asp platform
    idEDB-ID:27814
    last seen2016-02-03
    modified2006-05-03
    published2006-05-03
    reporterr0t
    sourcehttps://www.exploit-db.com/download/27814/
    titleCyberBuild - browse0.htm ProductIndex Parameter SQL Injection
  • descriptionCyberBuild 0 login.asp SessionID Parameter SQL Injection. CVE-2006-2179. Webapps exploit for asp platform
    idEDB-ID:27813
    last seen2016-02-03
    modified2006-05-03
    published2006-05-03
    reporterr0t
    sourcehttps://www.exploit-db.com/download/27813/
    titleCyberBuild - login.asp SessionID Parameter SQL Injection