23005Third-party advisory
http://secunia.com/advisories/23005 CVE-2006-6157
ContentNow 1.39 - 'pageid' SQL Injection
Record summary
CVE-2006-6157 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
SQL injection vulnerability in index.php in ContentNow 1.39 and earlier allows remote attackers to execute arbitrary SQL commands via the pageid parameter. NOTE: this issue can be leveraged for path disclosure with an invalid pageid parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBContentNow 1.39 - 'pageid' SQL InjectionExploitDB exploitby RevengeNot analyzed1 file
References
111925Third-party advisory
http://securityreason.com/securityalert/1925 1017265vdb entry
http://securitytracker.com/id?1017265 sourceforge.netConfirmation
http://sourceforge.net/project/shownotes.php?group_id=161604&release_id=465437 0xcafebabe.it
http://www.0xcafebabe.it/sploits/contentnow_139_sqlinj.pl 20061121 ContentNow CMS 1.39 Sql Injection + Path Disclosure Vulnerabilitiesmailing list
http://www.securityfocus.com/archive/1/452231/100/100/threaded 21237vdb entry
http://www.securityfocus.com/bid/21237 ADV-2006-4663vdb entry
http://www.vupen.com/english/advisories/2006/4663 contentnow-index-sql-injection(30459)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/30459 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2006-6157 2822exploit
https://www.exploit-db.com/exploits/2822