Exploitation Summary
EIP tracks 2 public exploits for CVE-2006-5954. PoCs published by ajann.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in NetVios News Application via the 'NewsID' parameter in page.asp. It allows an attacker to extract sensitive information such as usernames and passwords from the database.
Description
SQL injection vulnerability in page.asp in NetVIOS 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the NewsID parameter.
Exploits (2)
This exploit demonstrates a SQL injection vulnerability in NetVios News Application via the 'NewsID' parameter in page.asp. It allows an attacker to extract sensitive information such as usernames and passwords from the database.
This exploit demonstrates a SQL injection vulnerability in NetVios Portal's page.asp by injecting a UNION-based query to extract user credentials. The example query retrieves loginname and password from the users table.