Show filters
15 Total Results
Displaying 1-10 of 15
Sort by:
Attacker Value
Unknown
CVE-2009-0252
Disclosure Date: January 22, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in default.asp in Enthrallweb eReservations allow remote attackers to execute arbitrary SQL commands via the (1) Login parameter (aka username field) or the (2) Password parameter (aka password field). NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2006-6820
Disclosure Date: December 29, 2006 (last updated October 04, 2023)
myprofile.asp in Enthrallweb eCoupons does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account's username in a modified MM_recordId parameter.
0
Attacker Value
Unknown
CVE-2006-6821
Disclosure Date: December 29, 2006 (last updated October 04, 2023)
myprofile.asp in Enthrallweb eNews does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account's username in a modified MM_recordId parameter.
0
Attacker Value
Unknown
CVE-2006-6822
Disclosure Date: December 29, 2006 (last updated October 04, 2023)
myprofile.asp in Enthrallweb eClassifieds does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account's username in a modified MM_recordId parameter.
0
Attacker Value
Unknown
CVE-2006-6804
Disclosure Date: December 28, 2006 (last updated October 04, 2023)
SQL injection vulnerability in bus_details.asp in Dragon Business Directory - Pro (aka Dragon Internet Business Search Directory - Pro) 3.01.12 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter.
0
Attacker Value
Unknown
CVE-2006-6803
Disclosure Date: December 28, 2006 (last updated October 04, 2023)
SQL injection vulnerability in Types.asp in Enthrallweb eCars 1.0 allows remote attackers to execute arbitrary SQL commands via the Type_id parameter.
0
Attacker Value
Unknown
CVE-2006-6802
Disclosure Date: December 28, 2006 (last updated October 04, 2023)
SQL injection vulnerability in actualpic.asp in Enthrallweb ePages allows remote attackers to execute arbitrary SQL commands via the Biz_ID parameter.
0
Attacker Value
Unknown
CVE-2006-6806
Disclosure Date: December 28, 2006 (last updated October 04, 2023)
SQL injection vulnerability in newsdetail.asp in Enthrallweb eMates 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
0
Attacker Value
Unknown
CVE-2006-6805
Disclosure Date: December 28, 2006 (last updated October 04, 2023)
SQL injection vulnerability in newsdetail.asp in Enthrallweb eJobs allows remote attackers to execute arbitrary SQL commands via the ID parameter.
0
Attacker Value
Unknown
CVE-2006-6204
Disclosure Date: December 01, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Enthrallweb eHomes allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter to (a) dircat.asp; the (2) sid parameter to (b) dirSub.asp; the (3) TYPE_ID parameter to (c) types.asp; the (4) AD_ID parameter to (d) homeDetail.asp; the (5) cat parameter to (e) result.asp; the (6) compare, (7) clear, and (8) adID parameters to (f) compareHomes.asp; and the (9) aminprice, (10) amaxprice, and (11) abedrooms parameters to (g) result.asp.
0