Exploitation Summary
EIP tracks 1 public exploit for CVE-2005-4656. PoCs published by Devil-00.
AI-analyzed exploit summary This Perl script exploits SQL injection vulnerabilities in TClanPortal Version 3 to extract user credentials (username and MD5 password hash) via crafted UNION-based SQL queries. It targets the 'linkdl/index.php' endpoint with manipulated 'id' parameters.
Description
SQL injection vulnerability in index.php in TClanPortal 1.1.3 and earlier allows remote attackers to execute arbitrary SQL commands, and retrieve all usernames and passwords, via the id parameter.
Exploits (1)
This Perl script exploits SQL injection vulnerabilities in TClanPortal Version 3 to extract user credentials (username and MD5 password hash) via crafted UNION-based SQL queries. It targets the 'linkdl/index.php' endpoint with manipulated 'id' parameters.