CVE-2005-3996
Zen Cart < 1.2.6d - SQL Injection via admin_email Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-3996. PoCs published by rgod.
AI-analyzed exploit summary This PHP script exploits a blind SQL injection vulnerability in Zen-Cart <= 1.2.6d, allowing remote command execution. It includes functionality to disclose application paths and execute commands via crafted HTTP requests.
Description
SQL injection vulnerability in admin/password_forgotten.php in Zen Cart 1.2.6d and earlier allows remote attackers to execute arbitrary SQL commands via the admin_email parameter.
Exploits (1)
This PHP script exploits a blind SQL injection vulnerability in Zen-Cart <= 1.2.6d, allowing remote command execution. It includes functionality to disclose application paths and execute commands via crafted HTTP requests.