CVE-2005-3748
Tru-Zone Nuke ET 3.2 - SQL Injection via Search Module Query Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-3748. PoCs published by Lostmon.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in Nuke ET by injecting a UNION-based query into the 'query' field of the Search module. It extracts user credentials (user_id, username, user_password) from the 'nuke_users' table.
Description
SQL injection vulnerability in the Search module in Tru-Zone Nuke ET 3.2, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the query parameter.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in Nuke ET by injecting a UNION-based query into the 'query' field of the Search module. It extracts user credentials (user_id, username, user_password) from the 'nuke_users' table.