CVE-2006-6207
Evolve Merchant - SQL Injection via products.asp partno Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-6207. PoCs published by Aria-Security Team.
AI-analyzed exploit summary The provided text describes an SQL injection vulnerability in Evolve Shopping Cart, where the 'partno' parameter in 'products.asp' is not properly sanitized. The vendor disputes the vulnerability, but the advisory suggests potential for data compromise or further exploitation.
Description
SQL injection vulnerability in products.asp in Evolve shopping cart (aka Evolve Merchant) allows remote attackers to execute arbitrary SQL commands via the partno parameter. NOTE: the vendor disputes this issue, stating that it is a forced SQL error
Exploits (1)
The provided text describes an SQL injection vulnerability in Evolve Shopping Cart, where the 'partno' parameter in 'products.asp' is not properly sanitized. The vendor disputes the vulnerability, but the advisory suggests potential for data compromise or further exploitation.