{
    "id": "CVE-2006-6109",
    "published": "2006-11-26 22:07:00",
    "last_modified": "2026-06-16 22:32:29",
    "cvss_score": "7.5",
    "cvss_severity": "HIGH",
    "cvss_version": "2.0",
    "cvss_vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
    "cwe": "CWE-89",
    "description": "Multiple SQL injection vulnerabilities in CandyPress Store 3.5.2.14 allow remote attackers to execute arbitrary SQL commands via the (1) policy parameter in openPolicy.asp or the (2) brand parameter in prodList.asp.",
    "epss_score": "0.01435",
    "epss_percentile": "0.72376",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-10-11 18:17:05",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "candypress",
            "product": "candypress_store"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "29037",
            "title": "CandyPress Store 3.5.2 14 - 'openPolicy.asp?policy' SQL Injection",
            "date": "2006-11-15",
            "url": "https://www.exploit-db.com/exploits/29037"
        },
        {
            "source": "exploit-db",
            "ref_id": "29038",
            "title": "CandyPress Store 3.5.2 14 - 'prodList.asp?brand' SQL Injection",
            "date": "2006-11-15",
            "url": "https://www.exploit-db.com/exploits/29038"
        }
    ],
    "refs_list": [
        "http://marc.info/?l=bugtraq&m=116372253323469&w=2",
        "http://s-a-p.ca/index.php?page=OurAdvisories&id=25",
        "http://secunia.com/advisories/22954",
        "http://www.securityfocus.com/bid/21090/info",
        "http://www.vupen.com/english/advisories/2006/4577",
        "https://exchange.xforce.ibmcloud.com/vulnerabilities/30346",
        "http://marc.info/?l=bugtraq&m=116372253323469&w=2",
        "http://s-a-p.ca/index.php?page=OurAdvisories&id=25",
        "http://secunia.com/advisories/22954",
        "http://www.securityfocus.com/bid/21090/info",
        "http://www.vupen.com/english/advisories/2006/4577",
        "https://exchange.xforce.ibmcloud.com/vulnerabilities/30346"
    ]
}