CVE-2006-6109 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 1.4% (pctl 72)
Patch early
A public exploit exists.
Description
Multiple SQL injection vulnerabilities in CandyPress Store 3.5.2.14 allow remote attackers to execute arbitrary SQL commands via the (1) policy parameter in openPolicy.asp or the (2) brand parameter in prodList.asp.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 1.44% — more likely to be exploited than 72% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-11-26 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| candypress | candypress store |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | CandyPress Store 3.5.2 14 - 'openPolicy.asp?policy' SQL Injection | 2006-11-15 |
| exploit-db | CandyPress Store 3.5.2 14 - 'prodList.asp?brand' SQL Injection | 2006-11-15 |
References
- http://marc.info/?l=bugtraq&m=116372253323469&w=2
- http://s-a-p.ca/index.php?page=OurAdvisories&id=25
- http://secunia.com/advisories/22954
- http://www.securityfocus.com/bid/21090/info
- http://www.vupen.com/english/advisories/2006/4577
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30346
- http://marc.info/?l=bugtraq&m=116372253323469&w=2
- http://s-a-p.ca/index.php?page=OurAdvisories&id=25
- http://secunia.com/advisories/22954
- http://www.securityfocus.com/bid/21090/info
- http://www.vupen.com/english/advisories/2006/4577
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30346
→ the Explorer · watch your stack · NVD