5.1
CVSSv2

CVE-2006-3823

Published: 25/07/2006 Updated: 01/09/2015
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 520
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in index.php in GeodesicSolutions (1) GeoAuctions Premier 2.0.3 and (2) GeoClassifieds Basic 2.0.3 allows remote malicious users to execute arbitrary SQL commands via the b parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

geodesicsolutions geoauctions premier 2.0.3

geodesicsolutions geoclassifieds basic 2.0.3

Exploits

########################################################################################### #Exploit Title: GeoCore MAX DB Ver 733 - Time-Based Blind Injection #Official site: geodesicsolutionscom #Risk Level: High #Vendor : geodesicsolutionscom #Exploit Author: Esac #Homepage author : wwwiss4mma #Last Checked: 25/04/2014 ##### ...
source: wwwsecurityfocuscom/bid/19093/info GeodesicSolutions products are prone to multiple SQL-injection vulnerabilities because the applications fail to properly sanitize user-supplied input before using it in an SQL query A successful attack could allow an attacker to compromise the software, access or modify data, or exploit vuln ...

Github Repositories

Access to NVD, download XML files, parse it and stores in sqlite3 database

NVDparser (OBSOLETE DUE TO NVD CHANGING THE PROVIDED XML FILES) Summary This scripts access to NVD (National Vulnerability Database) web page, download XML files from nvdnistgov/downloadcfm, parses them and stores in sqlite3 database The script will not download files already downloaded if the update date is not more recent than the last time it was downloaded The