Exploitation Summary
EIP tracks 1 public exploit for CVE-2005-1071. PoCs published by CiNU5.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in JPortal 2.3.1, allowing an attacker to extract administrator credentials by injecting a UNION-based SQL query into the banner.php page.
Description
SQL injection vulnerability in banner.inc.php in JPortal Web Portal 2.3.1 allows remote attackers to execute arbitrary SQL commands via the haslo parameter.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by CiNU5 · textwebappsphp
https://www.exploit-db.com/exploits/25382
This exploit demonstrates an SQL injection vulnerability in JPortal 2.3.1, allowing an attacker to extract administrator credentials by injecting a UNION-based SQL query into the banner.php page.
Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:
JPortal 2.3.1
No auth needed
Prerequisites:
Access to the target URL (banner.php)
mistral-large-3 · analyzed Feb 16, 2026
Full analysis →
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/15476
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=111331738223323&w=2
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/14919
Scores
EPSS
0.0114
EPSS Percentile
63.4%
Details
Status
published
Published
Apr 12, 2005
Tracked Since
Feb 18, 2026