CVE-2006-6209
MidiCart ASP and ASP Plus Shopping Cart - SQL Injection via id2006quant, maingroup, or secondgroup Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-6209. PoCs published by Aria-Security Team.
AI-analyzed exploit summary The provided text describes an SQL injection vulnerability in MidiCart ASP, where the 'id2006quant' parameter in 'item_show.asp' is not properly sanitized. This allows attackers to manipulate SQL queries, potentially compromising the application or underlying database.
Description
Multiple SQL injection vulnerabilities in MidiCart ASP Shopping Cart and ASP Plus Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) id2006quant parameter to (a) item_show.asp, or the (2) maingroup or (3) secondgroup parameter to (b) item_list.asp. NOTE: the code_no parameter to Item_Show.asp is covered by CVE-2005-2601.
Exploits (1)
The provided text describes an SQL injection vulnerability in MidiCart ASP, where the 'id2006quant' parameter in 'item_show.asp' is not properly sanitized. This allows attackers to manipulate SQL queries, potentially compromising the application or underlying database.