Vulnerabilities > CVE-2006-6928 - SQL Injection and Cross-Site Scripting vulnerability in Grandora Rialto 1.6

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
grandora
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in Rialto 1.6 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to (a) listmain.asp or (b) searchmain.asp, the (2) the Keyword parameter to (c) searchkey.asp, or the (3) refno parameter to (d) forminfo.asp.

Vulnerable Configurations

Part Description Count
Application
Grandora
1

Exploit-Db

  • descriptionGrandora Rialto 1.6 searchkey.asp Keyword Parameter XSS. CVE-2006-6928. Webapps exploit for asp platform
    idEDB-ID:29115
    last seen2016-02-03
    modified2006-11-20
    published2006-11-20
    reporterlaurent gaffie
    sourcehttps://www.exploit-db.com/download/29115/
    titleGrandora Rialto 1.6 - searchkey.asp Keyword Parameter XSS
  • descriptionGrandora Rialto 1.6 listmain.asp cat Parameter XSS. CVE-2006-6928. Webapps exploit for asp platform
    idEDB-ID:29114
    last seen2016-02-03
    modified2006-11-20
    published2006-11-20
    reporterlaurent gaffie
    sourcehttps://www.exploit-db.com/download/29114/
    titleGrandora Rialto 1.6 listmain.asp cat Parameter XSS
  • descriptionGrandora Rialto 1.6 forminfo.asp refno Parameter XSS. CVE-2006-6928. Webapps exploit for asp platform
    idEDB-ID:29117
    last seen2016-02-03
    modified2006-11-20
    published2006-11-20
    reporterlaurent gaffie
    sourcehttps://www.exploit-db.com/download/29117/
    titleGrandora Rialto 1.6 forminfo.asp refno Parameter XSS
  • descriptionGrandora Rialto 1.6 searchmain.asp cat Parameter XSS. CVE-2006-6928. Webapps exploit for asp platform
    idEDB-ID:29116
    last seen2016-02-03
    modified2006-11-20
    published2006-11-20
    reporterlaurent gaffie
    sourcehttps://www.exploit-db.com/download/29116/
    titleGrandora Rialto 1.6 - searchmain.asp cat Parameter XSS