Vulnerabilities > CVE-2006-6147 - Input Validation vulnerability in Jiros Links Manager 1.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
jiros
exploit available

Summary

Multiple SQL injection vulnerabilities in JiRos Links Manager allow remote attackers to execute arbitrary SQL commands via the (1) LinkID parameter to openlink.asp or the (2) CategoryID parameter to viewlinks.asp.

Vulnerable Configurations

Part Description Count
Application
Jiros
1

Exploit-Db

  • descriptionJiRos Link Manager 1.0 viewlinks.asp CategoryID Parameter SQL Injection. CVE-2006-6147. Webapps exploit for asp platform
    idEDB-ID:29153
    last seen2016-02-03
    modified2006-11-21
    published2006-11-21
    reporterlaurent gaffie
    sourcehttps://www.exploit-db.com/download/29153/
    titleJiRos Link Manager 1.0 viewlinks.asp CategoryID Parameter SQL Injection
  • descriptionJiRos Link Manager 1.0 openlink.asp LinkID Parameter SQL Injection. CVE-2006-6147. Webapps exploit for asp platform
    idEDB-ID:29152
    last seen2016-02-03
    modified2006-11-21
    published2006-11-21
    reporterlaurent gaffie
    sourcehttps://www.exploit-db.com/download/29152/
    titleJiRos Link Manager 1.0 openlink.asp LinkID Parameter SQL Injection