Exploitation Summary
EIP tracks 1 public exploit for CVE-2005-4037. PoCs published by r0t.
AI-analyzed exploit summary The provided text describes an SQL injection vulnerability in Affiliate Manager PRO, where the 'pid' parameter in the 'ViewPaymentLog' action is not properly sanitized. This allows attackers to manipulate SQL queries, potentially leading to data disclosure or modification.
Description
SQL injection vulnerability in functions.php in Web4Future Affiliate Manager PRO 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter.
Exploits (1)
The provided text describes an SQL injection vulnerability in Affiliate Manager PRO, where the 'pid' parameter in the 'ViewPaymentLog' action is not properly sanitized. This allows attackers to manipulate SQL queries, potentially leading to data disclosure or modification.