CVE-2006-6349

PWP Technologies The Classified Ad System - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-6349. PoCs published by ajann.

AI-analyzed exploit summary This Perl script exploits a SQL injection vulnerability in The Classified Ad System 1.0 by injecting a UNION-based SQL query to extract admin credentials. It interacts with the target via HTTP and parses the response to display the username and password.

Description

Multiple SQL injection vulnerabilities in PWP Technologies The Classified Ad System allow remote attackers to execute arbitrary SQL commands via (1) the main parameter in a view action (includes/mainpage/view.asp) in default.asp or (2) a query in the search engine.

Exploits (1)

exploitdb WORKING POC VERIFIED
by ajann · perlwebappsasp
https://www.exploit-db.com/exploits/3015

This Perl script exploits a SQL injection vulnerability in The Classified Ad System 1.0 by injecting a UNION-based SQL query to extract admin credentials. It interacts with the target via HTTP and parses the response to display the username and password.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: The Classified Ad System 1.0
No auth needed
Prerequisites: Target must be running The Classified Ad System 1.0 · Target must have the vulnerable 'main' parameter exposed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/3015
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/5192
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/1975
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/21758
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/30443
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/452194/100/200/threaded
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23289
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/21198

Scores

EPSS 0.0199
EPSS Percentile 78.0%

Details

CWE
CWE-89
Status published
Products (1)
pwp_technologies/the_classified_ad_system
Published Dec 07, 2006
Tracked Since Feb 18, 2026