Vulnerability Key Information Vulnerability Title: Techno Dreams Articles&Papers Package <=v2.0 (ArticlesTableview.asp) Remote SQL Injection Vulnerability Release Date: 2006.09.22 Vulnerability Author: ajann CVE ID: CVE-2006-4891 CWE ID: CWE-89 Risk Level: Medium CVSS Base Score: 7.5/10 Impact Score: 6.4/10 - Confidentiality Impact: Partial - Integrity Impact: Partial - Availability Impact: Partial Exploitability Score: 10/10 - Attack Complexity: Low - Authentication Required: No required Vulnerability Description: - Affected Software: Techno Dreams Articles&Papers Package <=v2.0 - Vulnerability Type: Remote SQL Injection - Exploit Examples: - - Example Payload: - Additional Information: - Author states: "I'm not a Hacker!" - Suggestion: Change UserID Related Links: - Script Page: http://www.t-dreams.com