CVE-2006-6822 describes an improper input validation vulnerability in Enthrallweb eClassifieds. Specifically, the myprofile.asp component fails to adequately validate the MM_recordId parameter during profile updates, allowing an authenticated attacker to modify certain profile fields of other user accounts by manipulating this parameter with a target username. The vulnerability has a CVSS score of 3.5, indicating a medium severity. It can be exploited remotely by an authenticated user with medium attack complexity, resulting in partial integrity impact (modification of data) but no confidentiality or availability impact. While there is no evidence of active exploitation, an exploit for remote user password change exists on ExploitDB. There is no Metasploit or Nuclei module, and the CVE has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:enthrallweb:eclassifieds:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:S/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.