Vulnerabilities > CVE-2006-3474 - SQL Injection vulnerability in Belchior Foundry Vcard PRO

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
belchior-foundry
exploit available

Summary

Multiple SQL injection vulnerabilities in Belchior Foundry vCard PRO allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter to (a) gbrowse.php, (2) card_id parameter to (b) rating.php and (c) create.php, and the (3) event_id parameter to (d) search.php.

Vulnerable Configurations

Part Description Count
Application
Belchior_Foundry
1

Exploit-Db

  • descriptionvCard PRO 0 gbrowse.php cat_id Parameter SQL Injection. CVE-2006-3474. Webapps exploit for php platform
    idEDB-ID:28119
    last seen2016-02-03
    modified2006-06-19
    published2006-06-19
    reporterCrAzY CrAcKeR
    sourcehttps://www.exploit-db.com/download/28119/
    titlevCard PRO - gbrowse.php cat_id Parameter SQL Injection
  • descriptionvCard PRO 0 search.php event_id Parameter SQL Injection. CVE-2006-3474. Webapps exploit for php platform
    idEDB-ID:28122
    last seen2016-02-03
    modified2006-06-19
    published2006-06-19
    reporterCrAzY CrAcKeR
    sourcehttps://www.exploit-db.com/download/28122/
    titlevCard PRO - search.php event_id Parameter SQL Injection
  • descriptionvCard PRO 0 rating.php card_id Parameter SQL Injection. CVE-2006-3474. Webapps exploit for php platform
    idEDB-ID:28120
    last seen2016-02-03
    modified2006-06-19
    published2006-06-19
    reporterCrAzY CrAcKeR
    sourcehttps://www.exploit-db.com/download/28120/
    titlevCard PRO - rating.php card_id Parameter SQL Injection
  • descriptionvCard PRO 0 create.php card_id Parameter SQL Injection. CVE-2006-3474. Webapps exploit for php platform
    idEDB-ID:28121
    last seen2016-02-03
    modified2006-06-19
    published2006-06-19
    reporterCrAzY CrAcKeR
    sourcehttps://www.exploit-db.com/download/28121/
    titlevCard PRO - create.php card_id Parameter SQL Injection