CVE-2006-5945

MGinternet Car Site Manager - SQL Injection via p l typ or loc Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2006-5945. PoCs published by laurent gaffie.

AI-analyzed exploit summary The provided text describes SQL injection and XSS vulnerabilities in Car Site Manager, with example URLs demonstrating unsanitized input. No actual exploit code is present, only a vulnerability description and proof-of-concept URLs.

Description

Multiple SQL injection vulnerabilities in MGinternet Car Site Manager (CSM) allow remote attackers to execute arbitrary SQL commands via the (1) p parameter to (a) csm/asp/detail.asp, or the (2) l, (3) typ, or (4) loc parameter to (b) csm/asp/listings.asp.

Exploits (2)

exploitdb WRITEUP VERIFIED
by laurent gaffie · textwebappsasp
https://www.exploit-db.com/exploits/29014

The provided text describes SQL injection and XSS vulnerabilities in Car Site Manager, with example URLs demonstrating unsanitized input. No actual exploit code is present, only a vulnerability description and proof-of-concept URLs.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: Car Site Manager (version unspecified)
No auth needed
Prerequisites: Network access to the target application
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by laurent gaffie · textwebappsasp
https://www.exploit-db.com/exploits/29015

The provided text describes SQL injection and XSS vulnerabilities in Car Site Manager, with an example URL demonstrating SQL injection via the 'p' parameter. No actual exploit code is present.

Classification
Writeup 80%
Attack Type
Sqli | Xss
Complexity
Trivial
Reliability
Theoretical
Target: Car Site Manager
No auth needed
Prerequisites: Access to the vulnerable web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/451557/100/0/threaded
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22914
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/30273
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/1876
Vendor Advisory, URL Repurposed x_refsource_misc
http://s-a-p.ca/index.php?page=OurAdvisories&id=17
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/4532
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/21066

Scores

EPSS 0.0126
EPSS Percentile 65.8%

Details

Status published
Products (1)
mginternet/car_site_manager
Published Nov 17, 2006
Tracked Since Feb 18, 2026