peter bassill · operator
$ cve CVE-2006-6109 JSON

CVE-2006-6109 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 1.4% (pctl 72)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in CandyPress Store 3.5.2.14 allow remote attackers to execute arbitrary SQL commands via the (1) policy parameter in openPolicy.asp or the (2) brand parameter in prodList.asp.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS1.44% — more likely to be exploited than 72% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2006-11-26
Last modified2026-06-16

Affected (1)

VendorProduct
candypresscandypress store

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD