PT-2006-6739 · Unknown · Activenews Manager

·

CVE-2006-6094

·

Published

2006-11-24

·

Updated

2024-02-14

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ActiveNews Manager (affected versions not specified)
Description The issue concerns multiple SQL injection vulnerabilities. These vulnerabilities allow remote attackers to execute arbitrary SQL commands. The vulnerabilities can be exploited through specific parameters in different ASP pages, including the catID parameter to "activeNews categories.asp", the articleID parameter to "activeNews comments.asp", or the query parameter to "activenews search.asp".
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-6094

Affected Products

Activenews Manager