CVE-2006-2046 | Application Dynamics Cartweaver ColdFusion up to 2.16.11 results.cfm ProdID sql injection (EDB-4264 / XFDB-26060)

A vulnerability has been found in Application Dynamics Cartweaver ColdFusion up to 2.16.11 and classified as critical. This vulnerability affects unknown code of the file results.cfm. The manipulation of the argument ProdID leads to sql injection.

This vulnerability was named CVE-2006-2046. The attack can be initiated remotely. Furthermore, there is an exploit available.

CVE-2006-2046 | Application Dynamics Cartweaver ColdFusion up to 2.16.11 results.cfm ProdID sql injection (EDB-4264 / XFDB-26060)