Exploitation Summary
EIP tracks 1 public exploit for CVE-2004-1515. PoCs published by anonymous.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in the 'fsel' parameter of 'last.php', allowing unauthorized access to user credentials. The payload extracts usernames and passwords from the 'user' table by manipulating the SQL query.
Description
SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL statements via the fsel parameter, as demonstrated using last.php.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in the 'fsel' parameter of 'last.php', allowing unauthorized access to user credentials. The payload extracts usernames and passwords from the 'user' table by manipulating the SQL query.