Exploitation Summary
EIP tracks 2 public exploits for CVE-2005-4064. PoCs published by r0t.
AI-analyzed exploit summary The provided text describes a SQL injection vulnerability in A-FAQ 1.0 and earlier versions. It explains the vulnerability and provides a basic example URL for exploitation but lacks actual exploit code.
Description
Multiple SQL injection vulnerabilities in A-FAQ 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) faqid parameter to faqDspItem.asp and (2) catcode parameter to faqDsp.asp.
Exploits (2)
The provided text describes a SQL injection vulnerability in A-FAQ 1.0 and earlier versions. It explains the vulnerability and provides a basic example URL for exploitation but lacks actual exploit code.
The provided text describes a SQL injection vulnerability in A-FAQ 1.0 and earlier versions. It explains that the application fails to sanitize user input in the 'catcode' parameter, allowing attackers to manipulate SQL queries.