6.4
CVSSv2

CVE-2006-2046

Published: 26/04/2006 Updated: 11/10/2017
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 650
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Multiple SQL injection vulnerabilities in Application Dynamics Cartweaver ColdFusion 2.16.11 and previous versions allow remote malicious users to execute arbitrary SQL commands via the (1) category and (2) keywords parameters in (a) Results.cfm, and the (3) ProdID parameter in (b) Details.cfm.

Vulnerable Product Search on Vulmon Subscribe to Product

application dynamics cartweaver coldfusion

Exploits

author:meoconx[at]vnbrainnet product:CartWeaver main site:wwwcartweavercom 1with CFM CartWeaver: sql injection in: Detailscfm?ProdID=a' demo: wwwjbracingcouk/Detailscfm?ProdID=1' **************** exploit: wwwxxxcom/Detailscfm?ProdID=[sql query] **************** link admin: wwwxxxcom/[script path]/cw2/admin/ ***** ...
source: wwwsecurityfocuscom/bid/17941/info Cartweaver ColdFusion is prone to SQL-injection vulnerabilities These issues are due to the application's failure to properly sanitize user-supplied input before using it in SQL queries Successful exploits could allow an attacker to compromise the application, access or modify data, or exploi ...