CVE-2006-3886
Shalwan MusicBox <= 2.3.4 - SQL Injection via Page Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-3886. PoCs published by EllipSiS Security.
AI-analyzed exploit summary The provided text describes an SQL injection vulnerability in MusicBox version 2.3.4, where the 'page' parameter in the URL is not properly sanitized, allowing attackers to inject malicious SQL queries. The example URL demonstrates the vulnerability but does not include executable exploit code.
Description
SQL injection vulnerability in Shalwan MusicBox 2.3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter in a viewgallery action in a request for the top-level URI. NOTE: the start parameter/search action is already covered by CVE-2006-1807, and the show parameter/top action is already covered by CVE-2006-1360.
Exploits (1)
The provided text describes an SQL injection vulnerability in MusicBox version 2.3.4, where the 'page' parameter in the URL is not properly sanitized, allowing attackers to inject malicious SQL queries. The example URL demonstrates the vulnerability but does not include executable exploit code.