Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-4852. PoCs published by ajann.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Q-Shop v3.5's browse.asp page. The vulnerability allows an attacker to inject arbitrary SQL queries via the OrderBy parameter, potentially leading to unauthorized data access.
Description
SQL injection vulnerability in browse.asp in QuadComm Q-Shop 3.5 allows remote attackers to execute arbitrary SQL commands via the OrderBy parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Q-Shop v3.5's browse.asp page. The vulnerability allows an attacker to inject arbitrary SQL queries via the OrderBy parameter, potentially leading to unauthorized data access.