CVE-2006-6924
bitweaver <= 1.3.1 - Information Disclosure via SQL Error in sort_mode Parameter
Title source: llmExploitation Summary
EIP tracks 4 public exploits for CVE-2006-6924. PoCs published by laurent gaffie.
AI-analyzed exploit summary The provided text describes SQL injection and XSS vulnerabilities in Bitweaver 1.3.1 and prior versions due to insufficient input sanitization. It references a retired BID and includes a sample exploit URL for demonstration.
Description
bitweaver 1.3.1 and earlier allows remote attackers to obtain sensitive information via a sort_mode=-98 query string to (1) blogs/list_blogs.php, (2) fisheye/index.php, (3) wiki/orphan_pages.php, or (4) wiki/list_pages.php, which forces a SQL error. NOTE: the fisheye/list_galleries.php vector is already covered by CVE-2005-4380.
Exploits (4)
The provided text describes SQL injection and XSS vulnerabilities in Bitweaver 1.3.1 and prior versions due to insufficient input sanitization. It references a retired BID and includes a sample exploit URL for demonstration.
The provided text describes SQL injection and XSS vulnerabilities in Bitweaver 1.3.1 and prior versions due to insufficient input sanitization. It references a retired BID and includes a sample exploit URL for demonstration.
The provided text describes SQL injection and XSS vulnerabilities in Bitweaver 1.3.1 and prior versions due to insufficient input sanitization. It references a retired BID and includes a sample exploit URL for demonstration.
The provided text describes SQL injection and XSS vulnerabilities in Bitweaver 1.3.1 and prior versions due to insufficient input sanitization. It references a retired BID and includes a sample exploit URL for SQL injection.