- 34,644
 
- 0
 
- 18 Дек 2022
 
- EDB-ID
 - 29089
 
- Проверка EDB
 - 
	
		
			
- Пройдено
 
 
- Автор
 - LAURENT GAFFIE
 
- Тип уязвимости
 - WEBAPPS
 
- Платформа
 - ASP
 
- CVE
 - cve-2006-6094
 
- Дата публикации
 - 2006-11-18
 
		Код:
	
	source: https://www.securityfocus.com/bid/21167/info
   
Active News Manger is prone to multiple input-validation vulnerabilities, including SQL-injection issues and a cross-site scripting issue, because it fails to sufficiently sanitize user-supplied data.
   
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.
   
http://www.example.com/path/activeNews_categories.asp?catID=[SQL INJECTION]
	- Источник
 - www.exploit-db.com