CVE-2006-1685
APT-webshop-system <4.0 PRO, 3.0 BASIC, 3.0 LIGHT - SQL Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-1685. PoCs published by r0t.
AI-analyzed exploit summary The provided text describes SQL injection vulnerabilities in APT-webshop versions 3.0 light, 3.0 basic, and 4.0 pro. It includes example URLs demonstrating how unsanitized input in the 'group', 'seite', and 'id' parameters can be exploited.
Description
Multiple SQL injection vulnerabilities in modules.php in APT-webshop-system 4.0 PRO, 3.0 BASIC, and 3.0 LIGHT allow remote attackers to execute arbitrary SQL commands via the (1) group, (2) seite, and (3) id parameter, possibly involving the artikel functionality. NOTE: this vulnerability also allows resultant path disclosure when the SQL queries are invalid.
Exploits (1)
The provided text describes SQL injection vulnerabilities in APT-webshop versions 3.0 light, 3.0 basic, and 4.0 pro. It includes example URLs demonstrating how unsanitized input in the 'group', 'seite', and 'id' parameters can be exploited.