VulnerabilityModified
CVE-2006-6073
Multiple SQL injection vulnerabilities in Enthrallweb eShopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) ProductID parameter in productdetail.asp or the (2) categoryid parameter in products.asp.
HIGH 7.5EPSS 1.16%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.16%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple SQL injection vulnerabilities in Enthrallweb eShopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) ProductID parameter in productdetail.asp or the (2) categoryid parameter in products.asp.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.16% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- enthrallweb/eshopping cart
- Source
- cve@mitre.org
References
- http://aria-security.net/advisory/eShopping.txtBroken Link
- http://marc.info/?l=bugtraq&m=116353137028066&w=2Mailing List
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30262
- http://aria-security.net/advisory/eShopping.txtBroken Link
- http://marc.info/?l=bugtraq&m=116353137028066&w=2Mailing List
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30262
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.