Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-6446. PoCs published by boom3rang.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in CMS IWARE 5.0.4 by manipulating the 'D' parameter and other query parameters to extract user credentials via UNION-based SQLi. The PoC includes multiple examples with crafted payloads.
Description
SQL injection vulnerability in index.php in iWare Professional 5.0.4, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the D parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in CMS IWARE 5.0.4 by manipulating the 'D' parameter and other query parameters to extract user credentials via UNION-based SQLi. The PoC includes multiple examples with crafted payloads.