Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-0154. PoCs published by Aliaksandr Hartsuyeu.
AI-analyzed exploit summary The provided text describes an SQL injection vulnerability in 427BB versions 2.2 and 2.2.1, where unsanitized input in the ForumID parameter allows attackers to execute arbitrary SQL queries. The example URL demonstrates a UNION-based attack to extract user credentials.
Description
SQL injection vulnerability in showthread.php in 427BB 2.2 and 2.2.1 allows remote attackers to execute arbitrary SQL commands via the ForumID parameter.
Exploits (1)
The provided text describes an SQL injection vulnerability in 427BB versions 2.2 and 2.2.1, where unsanitized input in the ForumID parameter allows attackers to execute arbitrary SQL queries. The example URL demonstrates a UNION-based attack to extract user credentials.