peter bassill · operator
$ cve CVE-2006-6209 JSON

CVE-2006-6209 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 1.4% (pctl 72)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in MidiCart ASP Shopping Cart and ASP Plus Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) id2006quant parameter to (a) item_show.asp, or the (2) maingroup or (3) secondgroup parameter to (b) item_list.asp. NOTE: the code_no parameter to Item_Show.asp is covered by CVE-2005-2601.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS1.39% — more likely to be exploited than 72% of all CVEs
On CISA KEVno
Public exploityes
Published2006-12-01
Last modified2026-06-16

Affected (2)

VendorProduct
midicart softwaremidicart asp plus shopping cart
midicart softwaremidicart asp shopping cart

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD