CVE-2006-5945
MGinternet Car Site Manager - SQL Injection via p l typ or loc Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2006-5945. PoCs published by laurent gaffie.
AI-analyzed exploit summary The provided text describes SQL injection and XSS vulnerabilities in Car Site Manager, with example URLs demonstrating unsanitized input. No actual exploit code is present, only a vulnerability description and proof-of-concept URLs.
Description
Multiple SQL injection vulnerabilities in MGinternet Car Site Manager (CSM) allow remote attackers to execute arbitrary SQL commands via the (1) p parameter to (a) csm/asp/detail.asp, or the (2) l, (3) typ, or (4) loc parameter to (b) csm/asp/listings.asp.
Exploits (2)
The provided text describes SQL injection and XSS vulnerabilities in Car Site Manager, with example URLs demonstrating unsanitized input. No actual exploit code is present, only a vulnerability description and proof-of-concept URLs.
The provided text describes SQL injection and XSS vulnerabilities in Car Site Manager, with an example URL demonstrating SQL injection via the 'p' parameter. No actual exploit code is present.