CVE-2005-2683
PHPKit 1.6.1 - SQL Injection via Letter or IM Receiver Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-2683. PoCs published by phuket.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in PHPKit by injecting a malicious query into the 'letter' parameter. The payload attempts to extract the first character of the user password, confirming the vulnerability.
Description
Multiple SQL injection vulnerabilities in PHPKit 1.6.1 allow remote attackers to execute arbitrary SQL commands via the (1) letter parameter to login/member.php or (2) im_receiver parameter to login/imcenter.php.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in PHPKit by injecting a malicious query into the 'letter' parameter. The payload attempts to extract the first character of the user password, confirming the vulnerability.