CVE-2006-5892

ASPired2Poll < 1.0 - SQL Injection via MoreInfo.asp id Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-5892. PoCs published by ajann.

AI-analyzed exploit summary This Perl script exploits a SQL injection vulnerability in AspPired2 Poll <= 1.0 via the 'MoreInfo.asp' page to extract admin credentials. It performs a UNION-based SQL injection to retrieve the username and password from the 'user' table.

Description

SQL injection vulnerability in MoreInfo.asp in The Net Guys ASPired2Poll 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by ajann · perlwebappsasp
https://www.exploit-db.com/exploits/2746

This Perl script exploits a SQL injection vulnerability in AspPired2 Poll <= 1.0 via the 'MoreInfo.asp' page to extract admin credentials. It performs a UNION-based SQL injection to retrieve the username and password from the 'user' table.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: AspPired2 Poll <= 1.0
No auth needed
Prerequisites: Target server running AspPired2 Poll <= 1.0 · Network access to the target server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/451320/100/0/threaded
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/20987
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22796
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/4428
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/30160
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/2746

Scores

EPSS 0.0121
EPSS Percentile 64.6%

Details

Status published
Products (1)
the_net_guys/aspired2poll < 1.0
Published Nov 14, 2006
Tracked Since Feb 18, 2026