CVE-2006-1706
Shopweezle 2.0 - SQL Injection via itemID, itemgr, brandID, or album Parameters
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2006-1706. PoCs published by r0t.
AI-analyzed exploit summary The provided text describes a SQL injection vulnerability in ShopWeezle, where the 'itemID' parameter in 'memo.php' is not properly sanitized. It includes a generic example URL but lacks actual exploit code or technical details for execution.
Description
Multiple SQL injection vulnerabilities in Shopweezle 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) itemID parameter to (a) login.php and (b) memo.php; and the (2) itemgr, (3) brandID, and (4) album parameters to (c) index.php. NOTE: this issue also produces resultant full path disclosure from invalid SQL queries.
Exploits (3)
The provided text describes a SQL injection vulnerability in ShopWeezle, where the 'itemID' parameter in 'memo.php' is not properly sanitized. It includes a generic example URL but lacks actual exploit code or technical details for execution.
The provided text describes a SQL injection vulnerability in ShopWeezle, specifically in the 'itemID' parameter of the 'login.php' page. It lacks executable exploit code but outlines the vulnerability and potential impact.
The provided text describes SQL injection vulnerabilities in ShopWeezle, detailing vulnerable parameters in URLs. It does not include executable exploit code but outlines attack vectors.