CVE-2005-3676
phpwebthings 1.4.4 - SQL Injection via download.php file Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-3676. PoCs published by A.1.M.
AI-analyzed exploit summary The provided text describes an SQL injection vulnerability in phpWebThings, where the 'file' parameter in download.php is vulnerable to SQL injection. The example URL demonstrates how an attacker could inject arbitrary SQL commands.
Description
SQL injection vulnerability in download.php in PhpWebThings 1.4.4 allows remote attackers to execute arbitrary SQL commands via the file parameter.
Exploits (1)
The provided text describes an SQL injection vulnerability in phpWebThings, where the 'file' parameter in download.php is vulnerable to SQL injection. The example URL demonstrates how an attacker could inject arbitrary SQL commands.