Vulnerabilities > CVE-2006-5991 - Unspecified vulnerability in Cactusoft Cactushop
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Multiple SQL injection vulnerabilities in wwweb concepts CactuShop allow remote attackers to execute arbitrary SQL commands via the (1) prodtype parameter in prodtype.asp and the (2) product parameter in product.asp.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- http://aria-security.net/advisory/WWWeb%20Cocepts.txt
- http://secunia.com/advisories/22895
- http://www.securityfocus.com/bid/21076
- http://securityreason.com/securityalert/1887
- http://www.vupen.com/english/advisories/2006/4528
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30261
- http://www.securityfocus.com/archive/1/451513/100/100/threaded