CVE-2006-1098 describes multiple SQL injection vulnerabilities in NZ Ecommerce, specifically affecting the digital_builder nz_ecommerce product. Attackers can exploit these flaws by manipulating the informationID or ParentCategory parameters in index.php to execute arbitrary SQL commands. The vulnerability carries a CVSS score of 7.5, indicating a high severity with a network-based attack vector, low complexity, and potential for partial compromise of confidentiality, integrity, and availability. While the vendor disputed the issue, research suggests it is legitimate, and an exploit is available on ExploitDB, though there is no evidence of active exploitation, Metasploit modules, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:digital_builder:nz_ecommerce:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.