1700Third-party advisory
http://securityreason.com/securityalert/1700 CVE-2006-5217
Emek Portal 2.1 - 'Uyegiris.asp' SQL Injection
Record summary
CVE-2006-5217 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
SQL injection vulnerability in giris_yap.asp in Emek Portal 2.1 allows remote attackers to execute arbitrary SQL commands by simultaneously injecting into the user name and pass fields in uyegiris.asp, also known as the Kullanici Adi (k_a) and Sifre (sifre) parameters.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBEmek Portal 2.1 - 'Uyegiris.asp' SQL InjectionExploitDB exploitby Dj ReMixNot analyzed1 file
References
520061006 Emek Portal v2.1 SQL Injectionmailing list
http://www.securityfocus.com/archive/1/447914/100/0/threaded 20378vdb entry
http://www.securityfocus.com/bid/20378 emek-portal-uyegiris-sql-injection(29380)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/29380 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2006-5217