Vulnerabilities > CVE-2006-6776 - Input Validation vulnerability in Future Internet

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
future-internet
exploit available

Summary

Multiple SQL injection vulnerabilities in Future Internet allow remote attackers to execute arbitrary SQL commands via the (1) newsId or (2) categoryid parameter in a Portal.Showpage action in index.cfm, or (3) the langId parameter in index.cfm.

Vulnerable Configurations

Part Description Count
Application
Future_Internet
1

Exploit-Db

descriptionFuture Internet index.cfm Multiple Parameter SQL Injection. CVE-2006-6776. Webapps exploit for cfm platform
idEDB-ID:29334
last seen2016-02-03
modified2006-12-23
published2006-12-23
reporterLinux_Drox
sourcehttps://www.exploit-db.com/download/29334/
titleFuture Internet index.cfm Multiple Parameter SQL Injection