CVE-2005-4170
efiction 1.1 - SQL Injection via viewuser.php uid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-4170. PoCs published by [email protected].
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in eFiction, allowing an attacker to extract sensitive information such as passwords from the database. The PoC uses a UNION-based SQL injection to retrieve data from the 'fanfiction_authors' table.
Description
SQL injection vulnerability in eFiction 1.1 allows remote attackers to execute arbitrary SQL commands via the uid parameter to viewuser.php.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in eFiction, allowing an attacker to extract sensitive information such as passwords from the database. The PoC uses a UNION-based SQL injection to retrieve data from the 'fanfiction_authors' table.