Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-1109. PoCs published by nukedx.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in TotalECommerce, allowing an attacker to extract admin credentials via UNION-based SQLi. Includes a C decrypter for the retrieved hashed passwords.
Description
SQL injection vulnerability in index.asp in Total Ecommerce 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: it is not clear whether this report is associated with a specific product. If not, then it should not be included in CVE.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in TotalECommerce, allowing an attacker to extract admin credentials via UNION-based SQLi. Includes a C decrypter for the retrieved hashed passwords.