CVE-2006-1706

Shopweezle 2.0 - SQL Injection

Title source: llm

Description

Multiple SQL injection vulnerabilities in Shopweezle 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) itemID parameter to (a) login.php and (b) memo.php; and the (2) itemgr, (3) brandID, and (4) album parameters to (c) index.php. NOTE: this issue also produces resultant full path disclosure from invalid SQL queries.

Exploits (3)

exploitdb WRITEUP VERIFIED
by r0t · textwebappsphp
https://www.exploit-db.com/exploits/27612
exploitdb WRITEUP VERIFIED
by r0t · textwebappsphp
https://www.exploit-db.com/exploits/27613
exploitdb WRITEUP VERIFIED
by r0t · textwebappsphp
https://www.exploit-db.com/exploits/27614

Scores

EPSS 0.0190
EPSS Percentile 83.0%

Classification

Status draft

Affected Products (4)

kansok_communications/shopweezle
kansok_communications/shopweezle
kansok_communications/shopweezle
kansok_communications/shopweezle

Timeline

Published Apr 11, 2006
Tracked Since Feb 18, 2026