SQL injection vulnerability in articles.asp in Expinion.net iNews (1) Publisher...
Vulnerability Description
SQL injection vulnerability in articles.asp in Expinion.net iNews (1) Publisher (iNP) 2.5 and earlier, and possibly (2) News Manager, allows remote attackers to execute arbitrary SQL commands via the ex parameter. NOTE: early reports of this issue reported it as XSS, but this was erroneous. The original report was for News Manager, but there is strong evidence that the correct product is Publisher.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-6274
Credits & Attribution
No credits recorded in the NVD database.
References
- http://secunia.com/advisories/23123
- http://www.securityfocus.com/bid/21296
- http://www.aria-security.com/forum/showthread.php?t=40
- http://securityreason.com/securityalert/1956
- http://www.vupen.com/english/advisories/2006/4707
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30510
- http://attrition.org/pipermail/vim/2006-November/001147.html
- http://www.securityfocus.com/archive/1/452572/100/0/threaded
More from expinion.net
View All →Affected Vendor
expinion.net
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.