7.5
CVSSv2

CVE-2006-6927

Published: 13/01/2007 Updated: 16/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 785
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Rialto 1.6 allow remote malicious users to execute arbitrary SQL commands via (1) the uname (username) and (2) pword (passwd) fields in (a) admin/default.asp; the (3) ID parameter to (b) listfull.asp or (c) printmain.asp; the (4) cat parameter to (d) listmain.asp, (e) searchoption.asp, or (f) searchmain.asp; the (5) Keyword parameter to (g) searchkey.asp; the (6) area parameter to searchmain.asp or searchoption.asp; the (7) searchin parameter to searchkey.asp; or the (8) cost1, (9) cost2, (10) acreage1, or (11) squarefeet1 parameters to searchoption.asp. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

grandora rialto 1.6

Exploits

source: wwwsecurityfocuscom/bid/21191/info Grandora Rialto is prone to multiple input-validation vulnerabilities, including SQL-injection and cross-site scripting issues, because it fails to sufficiently sanitize user-supplied data Exploiting this issue could allow an attacker to steal cookie-based authentication credentials, compromi ...
source: wwwsecurityfocuscom/bid/21191/info Grandora Rialto is prone to multiple input-validation vulnerabilities, including SQL-injection and cross-site scripting issues, because it fails to sufficiently sanitize user-supplied data Exploiting this issue could allow an attacker to steal cookie-based authentication credentials, compro ...
source: wwwsecurityfocuscom/bid/21191/info Grandora Rialto is prone to multiple input-validation vulnerabilities, including SQL-injection and cross-site scripting issues, because it fails to sufficiently sanitize user-supplied data Exploiting this issue could allow an attacker to steal cookie-based authentication credentials, comp ...
source: wwwsecurityfocuscom/bid/21191/info Grandora Rialto is prone to multiple input-validation vulnerabilities, including SQL-injection and cross-site scripting issues, because it fails to sufficiently sanitize user-supplied data Exploiting this issue could allow an attacker to steal cookie-based authentication credentials, compromise ...
source: wwwsecurityfocuscom/bid/21191/info Grandora Rialto is prone to multiple input-validation vulnerabilities, including SQL-injection and cross-site scripting issues, because it fails to sufficiently sanitize user-supplied data Exploiting this issue could allow an attacker to steal cookie-based authentication credentials ...
source: wwwsecurityfocuscom/bid/21191/info Grandora Rialto is prone to multiple input-validation vulnerabilities, including SQL-injection and cross-site scripting issues, because it fails to sufficiently sanitize user-supplied data Exploiting this issue could allow an attacker to steal cookie-based authentication credentials, ...
source: wwwsecurityfocuscom/bid/21191/info Grandora Rialto is prone to multiple input-validation vulnerabilities, including SQL-injection and cross-site scripting issues, because it fails to sufficiently sanitize user-supplied data Exploiting this issue could allow an attacker to steal cookie-based authentication credentials, co ...