Unrated severityNVD Advisory· Published Apr 11, 2006· Updated Apr 16, 2026
CVE-2006-1706
CVE-2006-1706
Description
Multiple SQL injection vulnerabilities in Shopweezle 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) itemID parameter to (a) login.php and (b) memo.php; and the (2) itemgr, (3) brandID, and (4) album parameters to (c) index.php. NOTE: this issue also produces resultant full path disclosure from invalid SQL queries.
Affected products
4cpe:2.3:a:kansok_communications:shopweezle:2.0:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:kansok_communications:shopweezle:2.0:*:*:*:*:*:*:*
- cpe:2.3:a:kansok_communications:shopweezle:2.0_personal:*:*:*:*:*:*:*
- cpe:2.3:a:kansok_communications:shopweezle:2.0_professional:*:*:*:*:*:*:*
- cpe:2.3:a:kansok_communications:shopweezle:2.0_professional_plus:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- www.securityfocus.com/bid/17441nvdExploit
- secunia.com/advisories/19593nvdVendor Advisory
- pridels0.blogspot.com/2006/04/shopweezle-20-multiple-vuln.htmlnvd
- www.osvdb.org/24470nvd
- www.osvdb.org/24471nvd
- www.osvdb.org/24472nvd
- www.osvdb.org/24473nvd
- www.vupen.com/english/advisories/2006/1291nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/25723nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/25724nvd
News mentions
0No linked articles in our index yet.