Exploitation Summary
EIP tracks 1 public exploit for CVE-2004-2263. PoCs published by Noam Rathaus.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in PlaySMS version 0.7 and prior by injecting a malicious cookie value to manipulate the SQL query. The PoC sends a crafted HTTP request with a malicious cookie to trigger the vulnerability.
Description
SQL injection vulnerability in the valid function in fr_left.php in PlaySMS 0.7 and earlier allows remote attackers to modify SQL statements via the vc2 cookie.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in PlaySMS version 0.7 and prior by injecting a malicious cookie value to manipulate the SQL query. The PoC sends a crafted HTTP request with a malicious cookie to trigger the vulnerability.