CVE-2006-6349

PWP Technologies The Classified Ad System - SQL Injection

Title source: llm

Description

Multiple SQL injection vulnerabilities in PWP Technologies The Classified Ad System allow remote attackers to execute arbitrary SQL commands via (1) the main parameter in a view action (includes/mainpage/view.asp) in default.asp or (2) a query in the search engine.

Exploits (1)

exploitdb WORKING POC VERIFIED
by ajann · perlwebappsasp
https://www.exploit-db.com/exploits/3015

Scores

EPSS 0.0232
EPSS Percentile 84.8%

Details

CWE
CWE-89
Status published
Products (1)
pwp_technologies/the_classified_ad_system
Published Dec 07, 2006
Tracked Since Feb 18, 2026