Exploitation Summary
EIP tracks 4 public exploits for CVE-2006-3474. PoCs published by CrAzY CrAcKeR.
AI-analyzed exploit summary The provided text describes a SQL injection vulnerability in VCard PRO, where the 'event_id' parameter in 'search.php' is not properly sanitized. It lacks actual exploit code but references the vulnerability details.
Description
Multiple SQL injection vulnerabilities in Belchior Foundry vCard PRO allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter to (a) gbrowse.php, (2) card_id parameter to (b) rating.php and (c) create.php, and the (3) event_id parameter to (d) search.php.
Exploits (4)
The provided text describes a SQL injection vulnerability in VCard PRO, where the 'event_id' parameter in 'search.php' is not properly sanitized. It lacks actual exploit code but references the vulnerability details.
The provided text describes a SQL injection vulnerability in VCard PRO, where the 'card_id' parameter in 'rating.php' is not properly sanitized. It lacks actual exploit code but references the vulnerability details.
The provided text describes a SQL injection vulnerability in VCard PRO, where the 'cat_id' parameter in 'gbrowse.php' is not properly sanitized. It lacks actual exploit code, serving only as a vulnerability description.
The provided text describes a SQL injection vulnerability in VCard PRO, where the 'card_id' parameter in 'create.php' is not properly sanitized. It lacks actual exploit code but references the vulnerability and its potential impact.