CVE-2006-6911
Digitizing Quote And Ordering System 1.0 - Authenticated SQL Injection via ordernum Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-6911. PoCs published by ajann.
AI-analyzed exploit summary The exploit demonstrates SQL injection and XSS vulnerabilities in QUOTE&ORDERING SYSTEM 1.0 via the 'ordernum' parameter in search.asp. It includes functional payloads for both vulnerabilities, requiring prior authentication.
Description
SQL injection vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authenticated users to execute arbitrary SQL commands via the ordernum parameter.
Exploits (1)
The exploit demonstrates SQL injection and XSS vulnerabilities in QUOTE&ORDERING SYSTEM 1.0 via the 'ordernum' parameter in search.asp. It includes functional payloads for both vulnerabilities, requiring prior authentication.