CVE-2004-2716
PHPMyChat 0.14.5 - SQL Injection via usersL.php3 Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-2716. PoCs published by HEX.
AI-analyzed exploit summary The document describes multiple vulnerabilities in phpHeaven phpMyChat, including HTML injection, SQL injection, authentication bypass, and file disclosure. It provides example URLs for exploiting SQL injection but does not include executable exploit code.
Description
Multiple SQL injection vulnerabilities in usersL.php3 in PHPMyChat 0.14.5 allow remote attackers to execute arbitrary SQL commands via the (1) sortBy, (2) sortOrder, (3) startReg, (4) U, (5) LastCheck , and (6) R parameters.
Exploits (1)
The document describes multiple vulnerabilities in phpHeaven phpMyChat, including HTML injection, SQL injection, authentication bypass, and file disclosure. It provides example URLs for exploiting SQL injection but does not include executable exploit code.