CVE-2006-6220
Recipes Complete Website 1.1.14 - SQL Injection via recipeid or categoryid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-6220. PoCs published by GregStar.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in Recipes Complete Website 1.1.14, allowing unauthorized extraction of user credentials (login/password) via crafted UNION SELECT queries.
Description
Multiple SQL injection vulnerabilities in Recipes Website (Recipes Complete Website) 1.1.14 allow remote attackers to execute arbitrary SQL commands via the (1) recipeid parameter to recipe.php or the (2) categoryid parameter to list.php.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in Recipes Complete Website 1.1.14, allowing unauthorized extraction of user credentials (login/password) via crafted UNION SELECT queries.