CVE-2006-5943
Website Designs for Less Inventory Manager - SQL Injection via pictable picfield or where Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-5943. PoCs published by laurent gaffie.
AI-analyzed exploit summary The provided text describes SQL injection vulnerabilities in Inventory Manager, detailing vulnerable parameters in the 'imager.asp' endpoint. It includes example URLs demonstrating how unsanitized input can be exploited.
Description
Multiple SQL injection vulnerabilities in inventory/display/imager.asp in Website Designs for Less Inventory Manager allow remote attackers to execute arbitrary SQL commands via the (1) pictable, (2) picfield, or (3) where parameter.
Exploits (1)
The provided text describes SQL injection vulnerabilities in Inventory Manager, detailing vulnerable parameters in the 'imager.asp' endpoint. It includes example URLs demonstrating how unsanitized input can be exploited.