Vulnerability CVE-2006-6807


Published: 2006-12-28   Modified: 2012-02-12

Description:
SQL injection vulnerability in list.asp in Softwebs Nepal (aka Ananda Raj Pandey) Ananda Real Estate 3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the agent parameter.

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Softwebs nepal -> Ananda real estate 

 References:
http://www.securityfocus.com/bid/21771
http://www.vupen.com/english/advisories/2006/5179
https://www.exploit-db.com/exploits/3001

Copyright 2021, cxsecurity.com

 

Back to Top