Vulnerabilities > CVE-2006-6342 - SQL-Injection vulnerability in Klf-Realty
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Multiple SQL injection vulnerabilities in KLF-DESIGN (aka Kim L. Fraser) KLF-REALTY allow remote attackers to execute arbitrary SQL commands via the (1) category and (2) agent parameters in (a) search_listing.asp, and the (3) property_id parameter in (b) detail.asp.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description Klf-Realty 2.0 detail.asp property_id Parameter SQL Injection. CVE-2006-6342. Webapps exploit for asp platform id EDB-ID:29143 last seen 2016-02-03 modified 2006-11-20 published 2006-11-20 reporter laurent gaffie source https://www.exploit-db.com/download/29143/ title Klf-Realty 2.0 detail.asp property_id Parameter SQL Injection description Klf-Realty 2.0 search_listing.asp Multiple Parameter SQL Injection. CVE-2006-6342. Webapps exploit for asp platform id EDB-ID:29142 last seen 2016-02-03 modified 2006-11-20 published 2006-11-20 reporter laurent gaffie source https://www.exploit-db.com/download/29142/ title Klf-Realty 2.0 - search_listing.asp Multiple Parameter SQL Injection