Vulnerabilities > CVE-2006-2732 - SQL Injection vulnerability in Mini-NUKE Your_Account.ASP

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
mini-nuke
exploit available

Summary

SQL injection vulnerability in Your_Account.asp in Mini-Nuke 2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) yas_1, (2) yas_2, and (3) yas_3 parameters.

Vulnerable Configurations

Part Description Count
Application
Mini-Nuke
1

Exploit-Db

descriptionMini-NUKE 2.3 Your_Account.ASP Multiple SQL Injection Vulnerabilities. CVE-2006-2732. Webapps exploit for asp platform
idEDB-ID:27913
last seen2016-02-03
modified2006-05-29
published2006-05-29
reporterMustafa Can Bjorn
sourcehttps://www.exploit-db.com/download/27913/
titleMini-NUKE 2.3 Your_Account.ASP Multiple SQL Injection Vulnerabilities