Vulnerabilities > CVE-2006-3474 - SQL Injection vulnerability in Belchior Foundry Vcard PRO
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Multiple SQL injection vulnerabilities in Belchior Foundry vCard PRO allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter to (a) gbrowse.php, (2) card_id parameter to (b) rating.php and (c) create.php, and the (3) event_id parameter to (d) search.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description vCard PRO 0 gbrowse.php cat_id Parameter SQL Injection. CVE-2006-3474. Webapps exploit for php platform id EDB-ID:28119 last seen 2016-02-03 modified 2006-06-19 published 2006-06-19 reporter CrAzY CrAcKeR source https://www.exploit-db.com/download/28119/ title vCard PRO - gbrowse.php cat_id Parameter SQL Injection description vCard PRO 0 search.php event_id Parameter SQL Injection. CVE-2006-3474. Webapps exploit for php platform id EDB-ID:28122 last seen 2016-02-03 modified 2006-06-19 published 2006-06-19 reporter CrAzY CrAcKeR source https://www.exploit-db.com/download/28122/ title vCard PRO - search.php event_id Parameter SQL Injection description vCard PRO 0 rating.php card_id Parameter SQL Injection. CVE-2006-3474. Webapps exploit for php platform id EDB-ID:28120 last seen 2016-02-03 modified 2006-06-19 published 2006-06-19 reporter CrAzY CrAcKeR source https://www.exploit-db.com/download/28120/ title vCard PRO - rating.php card_id Parameter SQL Injection description vCard PRO 0 create.php card_id Parameter SQL Injection. CVE-2006-3474. Webapps exploit for php platform id EDB-ID:28121 last seen 2016-02-03 modified 2006-06-19 published 2006-06-19 reporter CrAzY CrAcKeR source https://www.exploit-db.com/download/28121/ title vCard PRO - create.php card_id Parameter SQL Injection