CVE-2006-6095 Information
Feb 14, 2021
cve
Description
Multiple SQL injection vulnerabilities in ActiveNews Manager allow remote attackers to execute arbitrary SQL commands via the (1) articleID parameter to activenews_view.asp or the (2) page parameter to default.asp. NOTE: the activeNews_categories.asp and activeNews_comments.asp vectors are already covered by CVE-2006-6094.
Reference
http://marc.info/?l=bugtraq&m=116387481223790&w=2 http://www.aria-security.com/forum/showthread.php?t=33 http://www.osvdb.org/31568 http://www.osvdb.org/31569 http://www.securityfocus.com/bid/21167 https://exchange.xforce.ibmcloud.com/vulnerabilities/30352
Share on: