CVE-2006-5962
Hpecs Shopping Cart - SQL Injection via Username, Password, or Search Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-5962. PoCs published by Security Access Point.
AI-analyzed exploit summary This exploit demonstrates SQL injection and authentication bypass vulnerabilities in HP eCS Shopping Cart. It provides specific payloads for bypassing login and injecting SQL queries via the search functionality.
Description
Multiple SQL injection vulnerabilities in Hpecs Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields in the (a) login screen, and (3) searchstring parameter in (b) insearch_list.asp.
Exploits (1)
This exploit demonstrates SQL injection and authentication bypass vulnerabilities in HP eCS Shopping Cart. It provides specific payloads for bypassing login and injecting SQL queries via the search functionality.