CVE-2005-3423
Subdreamer 2.2.1 - SQL Injection via Loginusername Parameter or Cookies
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-3423. PoCs published by RusH.
AI-analyzed exploit summary This exploit targets CVE-2005-3423, a SQL injection vulnerability in Subdreamer 2.2.1. It performs blind SQL injection to extract user passwords, checks for admin access, and uploads a malicious PHP file to achieve remote command execution.
Description
Multiple SQL injection vulnerabilities in Subdreamer 2.2.1 allow remote attackers to execute arbitrary SQL commands via (1) the loginusername parameter or (2) cookies to (a) subdreamer.php, (b) ipb2.php, (c) phpbb2.php, (d) vbulletin2.php, and (e) vbulletin3.php.
Exploits (1)
This exploit targets CVE-2005-3423, a SQL injection vulnerability in Subdreamer 2.2.1. It performs blind SQL injection to extract user passwords, checks for admin access, and uploads a malicious PHP file to achieve remote command execution.