Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-6822. PoCs published by ajann.
AI-analyzed exploit summary This HTML form exploits CVE-2006-6822 by submitting crafted input to 'myprofile.asp', likely targeting an SQL injection vulnerability in the 'MM_recordId' parameter. The form includes fields for user profile updates, with default values that may trigger the vulnerability.
Description
myprofile.asp in Enthrallweb eClassifieds does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account's username in a modified MM_recordId parameter.
Exploits (1)
This HTML form exploits CVE-2006-6822 by submitting crafted input to 'myprofile.asp', likely targeting an SQL injection vulnerability in the 'MM_recordId' parameter. The form includes fields for user profile updates, with default values that may trigger the vulnerability.