CVE-2002-1499
FactoSystem Weblog - SQL Injection via authornumber, discussblurbid, name, or email Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2002-1499. PoCs published by Matthew Murphy.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in FactoSystem Weblog. The crafted URL manipulates the 'authornumber' parameter to execute arbitrary SQL commands, including updating the 'root' user's password.
Description
Multiple SQL injection vulnerabilities in FactoSystem CMS allows remote attackers to perform unauthorized database actions via (1) the authornumber parameter in author.asp, (2) the discussblurbid parameter in discuss.asp, (3) the name parameter in holdcomment.asp, and (4) the email parameter in holdcomment.asp.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in FactoSystem Weblog. The crafted URL manipulates the 'authornumber' parameter to execute arbitrary SQL commands, including updating the 'root' user's password.