CVE-2005-3884
Zainu <= 2.0 - SQL Injection via Search Term and Start Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-3884. PoCs published by r0t.
AI-analyzed exploit summary The exploit demonstrates SQL injection in Zainu via the 'term' and 'start' parameters in the '/index.php' endpoint. It leverages unsanitized user input to manipulate SQL queries, potentially leading to data disclosure or modification.
Description
Multiple SQL injection vulnerabilities in the search action in Zainu 2.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) term and (2) start parameters to index.php.
Exploits (1)
The exploit demonstrates SQL injection in Zainu via the 'term' and 'start' parameters in the '/index.php' endpoint. It leverages unsanitized user input to manipulate SQL queries, potentially leading to data disclosure or modification.