CVE-2006-6204

Enthrallweb eHomes - SQL Injection via Multiple Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 4 public exploits for CVE-2006-6204. PoCs published by ajann, laurent gaffie.

AI-analyzed exploit summary This exploit demonstrates SQL injection and XSS vulnerabilities in Enthrallweb eHomes 1.0. The SQLi allows unauthorized data retrieval via a crafted URL parameter, while the XSS enables arbitrary script execution.

Description

Multiple SQL injection vulnerabilities in Enthrallweb eHomes allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter to (a) dircat.asp; the (2) sid parameter to (b) dirSub.asp; the (3) TYPE_ID parameter to (c) types.asp; the (4) AD_ID parameter to (d) homeDetail.asp; the (5) cat parameter to (e) result.asp; the (6) compare, (7) clear, and (8) adID parameters to (f) compareHomes.asp; and the (9) aminprice, (10) amaxprice, and (11) abedrooms parameters to (g) result.asp.

Exploits (4)

exploitdb WORKING POC VERIFIED
by ajann · textwebappsasp
https://www.exploit-db.com/exploits/2987

This exploit demonstrates SQL injection and XSS vulnerabilities in Enthrallweb eHomes 1.0. The SQLi allows unauthorized data retrieval via a crafted URL parameter, while the XSS enables arbitrary script execution.

Classification
Working Poc 90%
Attack Type
Sqli | Xss
Complexity
Trivial
Reliability
Reliable
Target: Enthrallweb eHomes 1.0
No auth needed
Prerequisites: Access to the target web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by laurent gaffie · textwebappsasp
https://www.exploit-db.com/exploits/29123

The provided text describes SQL injection vulnerabilities in eHome's 'result.asp' page due to improper input sanitization. It includes example URLs demonstrating how an attacker could inject SQL queries via the 'aminprice', 'amaxprice', and 'abedrooms' parameters.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: eHome (version not specified)
No auth needed
Prerequisites: Access to the vulnerable eHome application
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by laurent gaffie · textwebappsasp
https://www.exploit-db.com/exploits/29121

The provided text describes a vulnerability in eHome software, specifically SQL injection and XSS issues due to improper input sanitization. It includes a generic example URL for SQL injection but lacks actual exploit code.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: eHome (version not specified)
No auth needed
Prerequisites: Access to the vulnerable eHome application
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by laurent gaffie · textwebappsasp
https://www.exploit-db.com/exploits/29122

The provided text describes SQL injection vulnerabilities in eHome's compareHomes.asp page due to improper input sanitization. It includes example URLs demonstrating the vulnerability but lacks executable exploit code.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: eHome (version unspecified)
No auth needed
Prerequisites: Access to the vulnerable eHome web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/4643
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/21193
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/30419
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23016
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/452107/100/100/threaded
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/1942
URL Repurposed x_refsource_misc
http://s-a-p.ca/index.php?page=OurAdvisories&id=50

Scores

EPSS 0.0123
EPSS Percentile 64.9%

Details

Status published
Products (1)
enthrallweb/ehomes
Published Dec 01, 2006
Tracked Since Feb 18, 2026