CVE-2006-4871
Keyvan1 EShoppingPro 1.0 - SQL Injection via search_run.asp order Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4871. PoCs published by ajann.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in EShoppingPro by injecting a UNION-based query to retrieve admin credentials. The PoC URL manipulates the 'order' parameter to extract usernames and passwords from the 'admin' table.
Description
SQL injection vulnerability in search_run.asp in Keyvan1 (aka Keyvan Janghorbani) EShoppingPro 1.0 allows remote attackers to execute arbitrary SQL commands via the order parameter.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in EShoppingPro by injecting a UNION-based query to retrieve admin credentials. The PoC URL manipulates the 'order' parameter to extract usernames and passwords from the 'admin' table.