CVE-2006-0199
Mini-Nuke CMS System < 1.8.2 - SQL Injection via news.asp hid Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2006-0199. PoCs published by nukedx, DetMyl.
AI-analyzed exploit summary This exploit demonstrates SQL injection and unauthorized password change vulnerabilities in MiniNuke 1.8.2 and prior versions. The SQLi allows remote attackers to extract user credentials, while the password change flaw enables attackers to reset any user's password without authentication.
Description
SQL injection vulnerability in news.asp in Mini-Nuke CMS System 1.8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the hid parameter.
Exploits (2)
This exploit demonstrates SQL injection and unauthorized password change vulnerabilities in MiniNuke 1.8.2 and prior versions. The SQLi allows remote attackers to extract user credentials, while the password change flaw enables attackers to reset any user's password without authentication.
This Perl script exploits a SQL injection vulnerability in MiniNuke CMS (versions <= 1.8.2) to extract user password hashes by manipulating the 'hid' parameter in the 'news.asp' endpoint. It supports proxy usage and targets a specific user ID.