Vulnerabilities > CVE-2006-6791 - SQL Injection vulnerability in Chatwm 1.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
chatwm
exploit available

Summary

SQL injection vulnerability in SelGruFra.asp in chatwm 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) txtUse and (2) txtPas parameters.

Vulnerable Configurations

Part Description Count
Application
Chatwm
1

Exploit-Db

descriptionChatwm 1.0 SelGruFra.ASP SQL Injection Vulnerabilities. CVE-2006-6791. Webapps exploit for asp platform
idEDB-ID:29336
last seen2016-02-03
modified2006-12-24
published2006-12-24
reporterShaFuq31
sourcehttps://www.exploit-db.com/download/29336/
titleChatwm 1.0 SelGruFra.ASP SQL Injection Vulnerabilities