CVE-2006-2296
EDirectoryPro < 2.0 - SQL Injection via search_result.asp Keyword Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-2296. PoCs published by Dj_Eyes.
AI-analyzed exploit summary The provided text describes an SQL injection vulnerability in EDirectoryPro, where unsanitized user input in the 'keyword' parameter can be exploited to manipulate SQL queries. The example URL demonstrates a basic SQLi payload.
Description
SQL injection vulnerability in search_result.asp in EDirectoryPro 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the keyword parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
Exploits (1)
The provided text describes an SQL injection vulnerability in EDirectoryPro, where unsanitized user input in the 'keyword' parameter can be exploited to manipulate SQL queries. The example URL demonstrates a basic SQLi payload.