CVE-2006-3926
PhpProBid 5.24 - SQL Injection via View/Start/OrderType Parameters
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2006-3926. PoCs published by EllipSiS Security.
AI-analyzed exploit summary The provided text describes SQL injection vulnerabilities in PHP Pro Bid version 5.24, with example URLs demonstrating the attack vectors. It lacks executable exploit code but outlines the vulnerability details.
Description
Multiple SQL injection vulnerabilities in PhpProBid 5.24 allow remote attackers to execute arbitrary SQL commands via the (1) view or (2) start parameters to (a) viewfeedback.php or the (3) orderType parameter to (b) categories.php.
Exploits (2)
The provided text describes SQL injection vulnerabilities in PHP Pro Bid version 5.24, with example URLs demonstrating the attack vectors. It lacks executable exploit code but outlines the vulnerability details.
The provided text describes SQL injection and XSS vulnerabilities in PHP Pro Bid 5.24 due to improper input sanitization. It includes a sample SQL injection payload but lacks executable exploit code.