CVE-2006-2046
Cartweaver ColdFusion < 2.16.11 - SQL Injection via Category, Keywords, or ProdID Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2006-2046. PoCs published by meoconx, r0t.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in CartWeaver's Details.cfm page, allowing an attacker to extract admin credentials by manipulating the ProdID parameter. The PoC includes specific queries to retrieve the username and password from the database.
Description
Multiple SQL injection vulnerabilities in Application Dynamics Cartweaver ColdFusion 2.16.11 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) category and (2) keywords parameters in (a) Results.cfm, and the (3) ProdID parameter in (b) Details.cfm.
Exploits (2)
This exploit demonstrates a SQL injection vulnerability in CartWeaver's Details.cfm page, allowing an attacker to extract admin credentials by manipulating the ProdID parameter. The PoC includes specific queries to retrieve the username and password from the database.
The provided text describes SQL injection vulnerabilities in Cartweaver ColdFusion due to improper input sanitization. It includes example URLs demonstrating how an attacker could inject SQL queries via the 'category' and 'keywords' parameters.