Multiple SQL injection vulnerabilities in EImagePro allow remote attackers to execute arbitrary SQL commands via the (1) CatID parameter to subList.asp, (2) SubjectID parameter to imageList.asp, or (3) Pic parameter to view.asp.
References
Configurations
History
21 Nov 2024, 00:11
Type | Values Removed | Values Added |
---|---|---|
References | () http://downloads.securityfocus.com/vulnerabilities/exploits/eimagepro-xss.txt - Exploit | |
References | () http://secunia.com/advisories/20043 - Exploit, Vendor Advisory | |
References | () http://www.osvdb.org/25331 - | |
References | () http://www.osvdb.org/25332 - | |
References | () http://www.osvdb.org/25333 - | |
References | () http://www.securityfocus.com/bid/17911 - Exploit | |
References | () http://www.vupen.com/english/advisories/2006/1749 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/26343 - |
Information
Published : 2006-05-11 10:02
Updated : 2025-04-03 01:03
NVD link : CVE-2006-2300
Mitre link : CVE-2006-2300
CVE.ORG link : CVE-2006-2300
JSON object : View
Products Affected
keyvan1
- eimagepro
CWE