Vulnerabilities > CVE-2006-6070 - SQL-Injection vulnerability in ASP-Nuke

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
asp-nuke
exploit available

Summary

SQL injection vulnerability in module/account/register/register.asp in ASP Nuke 0.80 and earlier allows remote attackers to execute arbitrary SQL commands via the StateCode parameter.

Vulnerable Configurations

Part Description Count
Application
Asp-Nuke
1

Exploit-Db

descriptionASPNuke <= 0.80 (register.asp) Remote SQL Injection Vulnerability. CVE-2006-6070. Webapps exploit for asp platform
fileexploits/asp/webapps/2813.txt
idEDB-ID:2813
last seen2016-01-31
modified2006-11-19
platformasp
port
published2006-11-19
reporterajann
sourcehttps://www.exploit-db.com/download/2813/
titleASPNuke <= 0.80 register.asp Remote SQL Injection Vulnerability
typewebapps