Vulnerabilities > CVE-2006-3184 - Remote Security vulnerability in Asp Stats Generator

047910
CVSS 4.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
asp-stats-generator
exploit available

Summary

Direct static code injection vulnerability in ASP Stats Generator before 2.1.2 allows remote authenticated attackers to execute arbitrary ASP code via the strAsgSknPageBgColour parameter to settings_skin.asp, which is stored in inc_skin_file.asp. Upgrade to ASP Stats Generator version 2.1.2 : http://www.weppos.com/asg/en/download.asp

Vulnerable Configurations

Part Description Count
Application
Asp_Stats_Generator
1

Exploit-Db

descriptionASP Stats Generator <= 2.1.1 SQL Injection Vulnerabilities. CVE-2006-3184,CVE-2006-3580. Webapps exploit for asp platform
fileexploits/asp/webapps/1931.txt
idEDB-ID:1931
last seen2016-01-31
modified2006-06-19
platformasp
port
published2006-06-19
reporterHamid Ebadi
sourcehttps://www.exploit-db.com/download/1931/
titleASP Stats Generator <= 2.1.1 - SQL Injection Vulnerabilities
typewebapps