CVE-2006-6092
20/20 Auto Gallery - SQL Injection via vehiclelistings.asp Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-6092. PoCs published by laurent gaffie.
AI-analyzed exploit summary The provided text describes SQL injection vulnerabilities in 20/20 Auto Gallery, detailing multiple vulnerable parameters in the `vehiclelistings.asp` page. It lists URLs with injectable parameters but does not include actual exploit code or payloads.
Description
Multiple SQL injection vulnerabilities in vehiclelistings.asp in 20/20 Auto Gallery allow remote attackers to execute arbitrary SQL commands via the (1) vehicleID, (2) categoryID_list, (3) sale_type, (4) stock_number, (5) manufacturer, (6) model, (7) vehicleID, (8) year, (9) vin, and (10) listing_price parameters.
Exploits (1)
The provided text describes SQL injection vulnerabilities in 20/20 Auto Gallery, detailing multiple vulnerable parameters in the `vehiclelistings.asp` page. It lists URLs with injectable parameters but does not include actual exploit code or payloads.