CVE-2006-3184 Information
Feb 14, 2021
cve
Description
Direct static code injection vulnerability in ASP Stats Generator before 2.1.2 allows remote authenticated attackers to execute arbitrary ASP code via the strAsgSknPageBgColour parameter to settings_skin.asp which is stored in inc_skin_file.asp.
Reference
http://blog.asp-stats.com/index.php/2006/06/18/asp-stats-generator-v212/ http://secunia.com/advisories/20721 http://www.hamid.ir/security/aspstats.txt http://www.vupen.com/english/advisories/2006/2414 https://exchange.xforce.ibmcloud.com/vulnerabilities/27284 https://www.exploit-db.com/exploits/1931
Share on: