Vulnerabilities > CVE-2006-6342 - SQL-Injection vulnerability in Klf-Realty

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
klf-design
exploit available

Summary

Multiple SQL injection vulnerabilities in KLF-DESIGN (aka Kim L. Fraser) KLF-REALTY allow remote attackers to execute arbitrary SQL commands via the (1) category and (2) agent parameters in (a) search_listing.asp, and the (3) property_id parameter in (b) detail.asp.

Vulnerable Configurations

Part Description Count
Application
Klf-Design
1

Exploit-Db

  • descriptionKlf-Realty 2.0 detail.asp property_id Parameter SQL Injection. CVE-2006-6342. Webapps exploit for asp platform
    idEDB-ID:29143
    last seen2016-02-03
    modified2006-11-20
    published2006-11-20
    reporterlaurent gaffie
    sourcehttps://www.exploit-db.com/download/29143/
    titleKlf-Realty 2.0 detail.asp property_id Parameter SQL Injection
  • descriptionKlf-Realty 2.0 search_listing.asp Multiple Parameter SQL Injection. CVE-2006-6342. Webapps exploit for asp platform
    idEDB-ID:29142
    last seen2016-02-03
    modified2006-11-20
    published2006-11-20
    reporterlaurent gaffie
    sourcehttps://www.exploit-db.com/download/29142/
    titleKlf-Realty 2.0 - search_listing.asp Multiple Parameter SQL Injection